PT-2023-7452 · Zyxel · Zyxel Usg Flex+1

CVE-2023-22914

·

Publicado

2023-01-10

·

Atualizado

2023-05-04

CVSS v2.0

7.9

Alta

VetorAV:N/AC:M/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel USG FLEX series firmware versions 4.50 through 5.35 Zyxel VPN series firmware versions 4.30 through 5.35
Description A path traversal vulnerability in the account print.cgi CGI program could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the tmp directory by uploading a crafted file if the hotspot function were enabled. This issue is related to incorrect restriction of the path name to the tmp directory.
Recommendations For Zyxel USG FLEX series firmware versions 4.50 through 5.35, consider disabling the account print.cgi CGI program until a patch is available. For Zyxel VPN series firmware versions 4.30 through 5.35, restrict access to the tmp directory to minimize the risk of exploitation. As a temporary workaround, avoid using the hotspot function until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08493
CVE-2023-22914

Produtos afetados

Zyxel Usg Flex
Zyxel Vpn