PT-2024-6119 · Zyxel · Zyxel Atp Series+1

Alessandro Sgreccia

+1

·

Published

2024-06-26

·

Updated

2024-12-13

·

CVE-2024-7203

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel ATP series firmware versions from V4.60 through V5.38 Zyxel USG FLEX series firmware versions from V4.60 through V5.38
Description A post-authentication command injection issue exists in the firmware of Zyxel ATP and USG FLEX series devices. This could allow an authenticated attacker with administrator privileges to execute certain operating system commands on an affected device by executing a crafted CLI command. The vulnerability arises due to the failure to neutralize special elements used in the operating system command.
Recommendations For Zyxel ATP series firmware versions from V4.60 through V5.38, update to a version that contains a fix for this issue. For Zyxel USG FLEX series firmware versions from V4.60 through V5.38, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the CLI command to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07033
CVE-2024-7203

Affected Products

Zyxel Atp Series
Zyxel Usg Flex Series