PT-2023-7451 · Zyxel · Zyxel Usg Flex 50+3
Published
2023-01-10
·
Updated
2023-05-04
·
CVE-2023-22915
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel USG FLEX series firmware versions 4.50 through 5.35
Zyxel USG FLEX 50(W) firmware versions 4.30 through 5.35
Zyxel USG20(W)-VPN firmware versions 4.30 through 5.35
Zyxel VPN series firmware versions 4.30 through 5.35
Description
A buffer overflow vulnerability in the
fbwifi forward.cgi CGI program could allow a remote unauthenticated attacker to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device. The vulnerability is related to a buffer overflow in memory, which can be exploited by sending specially crafted HTTP requests.Recommendations
For Zyxel USG FLEX series firmware versions 4.50 through 5.35, consider disabling the Facebook WiFi function until a patch is available.
For Zyxel USG FLEX 50(W) firmware versions 4.30 through 5.35, consider disabling the Facebook WiFi function until a patch is available.
For Zyxel USG20(W)-VPN firmware versions 4.30 through 5.35, consider disabling the Facebook WiFi function until a patch is available.
For Zyxel VPN series firmware versions 4.30 through 5.35, consider disabling the Facebook WiFi function until a patch is available.
As a temporary workaround, consider restricting access to the
fbwifi forward.cgi CGI program to minimize the risk of exploitation.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Usg Flex 50
Zyxel Usg Flex Series
Zyxel Usg20(W)-Vpn
Zyxel Vpn Series