PT-2022-6319 · Zyxel · Zyxel Nwa110Ax
Luci Stanescu
·
Published
2022-08-22
·
Updated
2023-12-29
·
CVE-2022-45854
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel NWA110AX versions prior to 6.50(ABTG.0)C0
Description
The issue is related to an improper check for unusual conditions in the firmware, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker. Additionally, there is a vulnerability in the implementation of the command-line interface (CLI) of Zyxel network device firmware, related to the failure to neutralize special elements used in the command of the operating system, which could allow a remote attacker to execute arbitrary commands.
Recommendations
For versions prior to 6.50(ABTG.0)C0, update to version 6.50(ABTG.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable AP to minimize the risk of exploitation. Avoid using the vulnerable CLI interface until the issue is resolved.
Fix
Improper Check for Exceptional Conditions
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zyxel Nwa110Ax