The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:NZyxel Pmg5318 B20a Firmware
OSZyxelv100aanc0b5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2015-6016CRITICAL9.8PL ✓same product
Zyxel ZyNOS — domyślne hasło '1234' umożliwia pełny dostęp administracyjny
CVE-2015-6018CRITICAL9.8PL ✓same product
Command injection w ZyXEL PMG5318-B20A — RCE przez parametr PingIPAddr
CVE-2015-6020HIGH8.0same product
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative...
CVE-2015-7256MEDIUM5.9same product
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG...
CVE-2023-27992CRITICAL9.8⚠ KEVPL ✓same vendor
Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542