PT-2023-8184 · Zyxel · Zyxel Nas542+1

Maxim Suslov

·

Published

2023-11-30

·

Updated

2023-12-05

·

CVE-2023-35137

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zyxel NAS326 version V5.21(AAZF.14)C0 Zyxel NAS542 version V5.21(ABAG.11)C0
Description The issue is related to an improper authentication vulnerability in the authentication module of the Zyxel NAS326 and NAS542 firmware. This vulnerability could allow an unauthenticated attacker to obtain system information by sending a crafted URL to a vulnerable device. The vulnerability is associated with deficiencies in the authentication procedure, which can be exploited to gain unauthorized access to the device.
Recommendations For Zyxel NAS326 version V5.21(AAZF.14)C0, consider disabling the authentication module until a patch is available. For Zyxel NAS542 version V5.21(ABAG.11)C0, restrict access to the device to minimize the risk of exploitation. As a temporary workaround, avoid using the vulnerable firmware versions until a fixed version is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00172
CVE-2023-35137

Affected Products

Zyxel Nas326
Zyxel Nas542