PT-2020-15703 · Zyxel · Zyxel Vmg5313-B30B

Published

2020-09-02

·

Updated

2020-09-11

·

CVE-2020-24355

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG5313-B30B router versions 5.13(ABCJ.6)b3 1127 and possibly earlier
Description The issue concerns insecure permissions that allow regular and other users to create new users with elevated privileges. This is achieved by modifying the FirstIndex field in the JSON data sent during account creation via a POST request. A similar vulnerability may also exist for account deletion.
Recommendations For version 5.13(ABCJ.6)b3 1127 and possibly earlier, consider restricting access to the account creation feature until a fix is available, and avoid using the FirstIndex field in the JSON data for account creation. As a temporary workaround, restrict user privileges to prevent exploitation.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24355

Affected Products

Zyxel Vmg5313-B30B