PT-2024-9042 · Zyxel · Zyxel Vmg4005-B50A
Erik De Jong
·
Published
2024-12-03
·
Updated
2025-01-21
·
CVE-2024-9200
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0
Description:
The issue is related to a post-authentication command injection vulnerability in the
host parameter of the diagnostic function. This vulnerability could allow an authenticated attacker with administrator privileges to execute operating system commands on a vulnerable device. The vulnerability is due to the lack of measures to neutralize special elements used in the operating system command.Recommendations:
For Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0, consider disabling the diagnostic function temporarily until a patch is available. Restrict access to the
host parameter in the diagnostic function to minimize the risk of exploitation. Avoid using the host parameter in the affected diagnostic function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Vmg4005-B50A