PT-2022-6319 · Zyxel · Zyxel Nwa110Ax

Luci Stanescu

·

Published

2022-08-22

·

Updated

2023-12-29

·

CVE-2022-45854

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel NWA110AX versions prior to 6.50(ABTG.0)C0
Description The issue is related to an improper check for unusual conditions in the firmware, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker. Additionally, there is a vulnerability in the implementation of the command-line interface (CLI) of Zyxel network device firmware, related to the failure to neutralize special elements used in the command of the operating system, which could allow a remote attacker to execute arbitrary commands.
Recommendations For versions prior to 6.50(ABTG.0)C0, update to version 6.50(ABTG.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable AP to minimize the risk of exploitation. Avoid using the vulnerable CLI interface until the issue is resolved.

Fix

Improper Check for Exceptional Conditions

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-00838
CVE-2022-45854

Affected Products

Zyxel Nwa110Ax