First published: Tue Jan 17 2023(Updated: )
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability to access the root file system by creating a symbolic link on external storage media, such as a USB flash drive, and then logging into the FTP server on a vulnerable device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel AX7501-B0 firmware | <5.17\(abpc.3\)c0 | |
Zyxel AX7501-B0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-45440.
The severity of CVE-2022-45440 is medium with a CVSS score of 4.4.
The vulnerability allows a local authenticated attacker with administrator privileges to access the root file system by creating symbolic links on external storage media.
Yes, the Zyxel AX7501-B0 firmware version prior to V5.17(ABPC.3)C0 is affected by this vulnerability.
An attacker with administrator privileges can abuse the vulnerability to access the root file system by creating symbolic links on external storage media.