A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HZyxel Nbg6818
HWZyxelall versionsZyxel Nbg6818 Firmware
OSZyxel< 1.00\(absc.5\)c0Zyxel Nbg7815
HWZyxelall versionsZyxel Nbg7815 Firmware
OSZyxel< 1.00\(absk.7\)c0Zyxel Wsq20
HWZyxelall versionsZyxel Wsq20 Firmware
OSZyxel< 1.00\(abof.11\)c0Zyxel Wsq50
HWZyxelall versionsZyxel Wsq50 Firmware
OSZyxel< 2.20\(abkj.7\)c0Zyxel Wsq60
HWZyxelall versionsZyxel Wsq60 Firmware
OSZyxel< 2.20\(abnd.8\)c0Zyxel Wsr30
HWZyxelall versionsZyxel Wsr30 Firmware
OSZyxel< 1.00\(abmy.12\)c0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
Related vulnerabilities
CVE-2023-27992CRITICAL9.8⚠ KEVPL ✓same vendor
Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542
CVE-2023-33010CRITICAL9.8⚠ KEVPL ✓same vendor
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia (firewalle/VPN)
CVE-2023-33009CRITICAL9.8⚠ KEVPL ✓same vendor
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia
CVE-2023-28771CRITICAL9.8⚠ KEVPL ✓same vendor
Zyxel Firewall/VPN — zdalny command injection bez uwierzytelnienia (RCE)
CVE-2022-30525CRITICAL9.8⚠ KEVPL ✓same vendor
Command injection w firmware Zyxel USG FLEX i VPN — zdalne wykonanie poleceń OS