PT-2023-2585 · Zyxel · Zyxel Nbg-418N

Toni Koivunen

·

Published

2023-01-10

·

Updated

2023-05-06

·

CVE-2023-22924

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0
Description A buffer overflow vulnerability could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device. The vulnerability is related to the lack of input size validation, which can be exploited by a remote attacker to disrupt the service.
Recommendations For Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0, update the firmware to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI interface to minimize the risk of exploitation. Avoid executing crafted CLI commands on the vulnerable device until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-02401
CVE-2023-22924

Affected Products

Zyxel Nbg-418N