Post-Authentication Command Injection Vulnerability Affects Zyxel ATP Series Firmware
CVE-2024-7203
7.2HIGH
Key Information:
- Vendor
Zyxel
- Vendor
- CVE Published:
- 3 September 2024
What is CVE-2024-7203?
A post-authentication command injection vulnerability exists in Zyxel ATP and USG FLEX series firmware that could allow an authenticated attacker with administrator privileges to execute arbitrary operating system commands. This vulnerability arises when a crafted command is executed within the command-line interface, potentially compromising the integrity and security of the affected devices. Users are advised to review their current firmware versions and apply necessary updates to mitigate potential risks.
Affected Version(s)
ATP series firmware versions V4.60 through V5.38
USG FLEX series firmware versions V4.60 through V5.38