PT-2023-8711 · Zyxel · Nwa50Ax+6
Atdog
+1
·
Published
2023-11-30
·
Updated
2025-01-21
·
CVE-2023-6398
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ZyXEL USG FLEX versions 4.50 through 5.37 Patch 1
ZyXEL USG FLEX 50(W)/USG20(W)-VPN versions 4.16 through 5.37 Patch 1
ZyXEL USG FLEX H versions 1.10 through 1.10 Patch 1
ZyXEL ATP series firmware versions 4.32 through 5.37 Patch 1
NWA50AX firmware versions through 6.29(ABYW.3)
WAC500 firmware versions through 6.65(ABVS.1)
WAX300H firmware versions through 6.60(ACHF.1)
WBE660S firmware versions through 6.65(ACGG.1)
Description
The issue is related to a post-authentication command injection vulnerability in the file upload binary, allowing an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device via FTP. This can be achieved by exploiting the vulnerability in the file upload process, which does not properly neutralize special elements used in the command.
Recommendations
For ZyXEL USG FLEX versions 4.50 through 5.37 Patch 1, update to a version later than 5.37 Patch 1.
For ZyXEL USG FLEX 50(W)/USG20(W)-VPN versions 4.16 through 5.37 Patch 1, update to a version later than 5.37 Patch 1.
For ZyXEL USG FLEX H versions 1.10 through 1.10 Patch 1, update to a version later than 1.10 Patch 1.
For ZyXEL ATP series firmware versions 4.32 through 5.37 Patch 1, update to a version later than 5.37 Patch 1.
For NWA50AX firmware versions through 6.29(ABYW.3), update to a version later than 6.29(ABYW.3).
For WAC500 firmware versions through 6.65(ABVS.1), update to a version later than 6.65(ABVS.1).
For WAX300H firmware versions through 6.60(ACHF.1), update to a version later than 6.60(ACHF.1).
For WBE660S firmware versions through 6.65(ACGG.1), update to a version later than 6.65(ACGG.1).
As a temporary workaround, consider restricting access to the FTP service until a patch is available.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nwa50Ax
Wac500
Wax300H
Wbe660S
Zyxel Atp Series
Zyxel Usg Flex
Zyxel Usg Flex 50(W)/Usg20(W)-Vpn