PT-2022-7090 · Zyxel · Zyxel Nbg7510

Alexander Traud

·

Published

2022-12-20

·

Updated

2022-12-29

·

CVE-2022-38546

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel NBG7510 versions prior to V1.00(ABZY.3)C0
Description The issue is related to a DNS misconfiguration in the Zyxel NBG7510 firmware, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode. This is due to insufficient access control.
Recommendations For versions prior to V1.00(ABZY.3)C0, update the firmware to V1.00(ABZY.3)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the AP mode until the update is applied.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2023-07565
CVE-2022-38546

Affected Products

Zyxel Nbg7510