PT-2022-6629 · Zyxel · Zyxel Dx5401-B0
Published
2022-02-15
·
Updated
2025-01-31
·
CVE-2023-28770
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZyXEL DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0
Description
The issue is related to insufficient protection of service data in the CGI "Export Log" component of the ZyXEL DX5401-B0 firmware. This could allow a remote unauthenticated attacker to read system files and retrieve the supervisor's password from an encrypted file. The attacker can exploit this issue to gain unauthorized access to protected information.
Recommendations
For ZyXEL DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0, update to version V5.17(ABYO.1)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Export Log" CGI component and the "zcmd" binary to minimize the risk of exploitation. Avoid using the affected firmware until the issue is resolved.
Exploit
Fix
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zyxel Dx5401-B0