PT-2020-15703 · Zyxel · Zyxel Vmg5313-B30B
Published
2020-09-02
·
Updated
2020-09-11
·
CVE-2020-24355
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel VMG5313-B30B router versions 5.13(ABCJ.6)b3 1127 and possibly earlier
Description
The issue concerns insecure permissions that allow regular and other users to create new users with elevated privileges. This is achieved by modifying the
FirstIndex field in the JSON data sent during account creation via a POST request. A similar vulnerability may also exist for account deletion.Recommendations
For version 5.13(ABCJ.6)b3 1127 and possibly earlier, consider restricting access to the account creation feature until a fix is available, and avoid using the
FirstIndex field in the JSON data for account creation. As a temporary workaround, restrict user privileges to prevent exploitation.Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Vmg5313-B30B