PT-2024-10082 · Zyxel · Zyxel Wbe530+1

Alessandro Sgreccia

·

Published

2024-12-10

·

Updated

2025-02-07

·

CVE-2024-12398

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel WBE530 firmware versions through 7.00(ACLE.3) Zyxel WBE660S firmware versions through 6.70(ACGG.2)
Description An improper privilege management vulnerability in the web management interface could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
Recommendations For Zyxel WBE530 firmware versions through 7.00(ACLE.3), update to a version that contains a fix for this issue. For Zyxel WBE660S firmware versions through 6.70(ACGG.2), update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the web management interface until a patch is available. Avoid using the vulnerable web management interface to upload configuration files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-00255
CVE-2024-12398

Affected Products

Zyxel Wbe530
Zyxel Wbe660S