PT-2022-7090 · Zyxel · Zyxel Nbg7510
Alexander Traud
·
Published
2022-12-20
·
Updated
2022-12-29
·
CVE-2022-38546
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel NBG7510 versions prior to V1.00(ABZY.3)C0
Description
The issue is related to a DNS misconfiguration in the Zyxel NBG7510 firmware, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode. This is due to insufficient access control.
Recommendations
For versions prior to V1.00(ABZY.3)C0, update the firmware to V1.00(ABZY.3)C0 or later to resolve the issue. As a temporary workaround, consider restricting access to the AP mode until the update is applied.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Nbg7510