PT-2024-6119 · Zyxel · Zyxel Atp Series+1
Alessandro Sgreccia
+1
·
Published
2024-06-26
·
Updated
2024-12-13
·
CVE-2024-7203
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel ATP series firmware versions from V4.60 through V5.38
Zyxel USG FLEX series firmware versions from V4.60 through V5.38
Description
A post-authentication command injection issue exists in the firmware of Zyxel ATP and USG FLEX series devices. This could allow an authenticated attacker with administrator privileges to execute certain operating system commands on an affected device by executing a crafted CLI command. The vulnerability arises due to the failure to neutralize special elements used in the operating system command.
Recommendations
For Zyxel ATP series firmware versions from V4.60 through V5.38, update to a version that contains a fix for this issue.
For Zyxel USG FLEX series firmware versions from V4.60 through V5.38, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the CLI command to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Atp Series
Zyxel Usg Flex Series