PT-2024-10082 · Zyxel · Zyxel Wbe530+1
Alessandro Sgreccia
·
Published
2024-12-10
·
Updated
2025-02-07
·
CVE-2024-12398
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel WBE530 firmware versions through 7.00(ACLE.3)
Zyxel WBE660S firmware versions through 6.70(ACGG.2)
Description
An improper privilege management vulnerability in the web management interface could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
Recommendations
For Zyxel WBE530 firmware versions through 7.00(ACLE.3), update to a version that contains a fix for this issue.
For Zyxel WBE660S firmware versions through 6.70(ACGG.2), update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the web management interface until a patch is available.
Avoid using the vulnerable web management interface to upload configuration files until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Wbe530
Zyxel Wbe660S