PT-2023-22605 · Zyxel · Zyxel Atp Series+3
Fabiano Golluscio
·
Published
2023-05-29
·
Updated
2026-05-15
·
CVE-2023-30253
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dolibarr versions prior to 17.0.1
Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series (affected versions not specified)
Description
The issue allows remote code execution by an authenticated user via an uppercase manipulation in injected data, such as using
<?PHP instead of <?php. This can be exploited in certain Zyxel products, including the ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series, although specific details about the exploitation in these products are not provided.Recommendations
For Dolibarr versions prior to 17.0.1, update to version 17.0.1 or later to resolve the issue.
For Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Usg Flex 50(W) Series
Usg Flex H Series
Usg20(W)-Vpn Series
Zyxel Atp Series