PT-2023-2585 · Zyxel · Zyxel Nbg-418N
Toni Koivunen
·
Published
2023-01-10
·
Updated
2023-05-06
·
CVE-2023-22924
CVSS v2.0
6.3
Medium
| Vector | AV:N/AC:M/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0
Description
A buffer overflow vulnerability could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device. The vulnerability is related to the lack of input size validation, which can be exploited by a remote attacker to disrupt the service.
Recommendations
For Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0, update the firmware to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI interface to minimize the risk of exploitation. Avoid executing crafted CLI commands on the vulnerable device until the issue is resolved. At the moment, there is no information about additional mitigation measures.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Nbg-418N