First published: Tue Feb 07 2023(Updated: )
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel NWA110AX | <=6.45\(abtg.0\)c0 | |
Zyxel NWA110AX firmware | ||
Zyxel NWA210AX | <=6.45\(abtd.0\)c0 | |
Zyxel NWA210AX Firmware | ||
Zyxel WAX510D firmware | <=6.45\(abtf.0\)c0 | |
Zyxel WAX510D firmware | ||
Zyxel WAX610D | <=6.45\(abte.0\)c0 | |
Zyxel WAX610D Firmware | ||
Zyxel WAX630S Firmware | <=6.45\(abzd.0\)c0 | |
Zyxel WAX630S Firmware | ||
Zyxel WAX650S Firmware | <=6.45\(abrm.0\)c0 | |
Zyxel WAX650S Firmware | ||
All of | ||
Zyxel NWA110AX | <=6.45\(abtg.0\)c0 | |
Zyxel NWA110AX firmware | ||
All of | ||
Zyxel NWA210AX | <=6.45\(abtd.0\)c0 | |
Zyxel NWA210AX Firmware | ||
All of | ||
Zyxel WAX510D firmware | <=6.45\(abtf.0\)c0 | |
Zyxel WAX510D firmware | ||
All of | ||
Zyxel WAX610D | <=6.45\(abte.0\)c0 | |
Zyxel WAX610D Firmware | ||
All of | ||
Zyxel WAX630S Firmware | <=6.45\(abzd.0\)c0 | |
Zyxel WAX630S Firmware | ||
All of | ||
Zyxel WAX650S Firmware | <=6.45\(abrm.0\)c0 | |
Zyxel WAX650S Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45854 is an improper check for unusual conditions in Zyxel NWA110AX firmware versions prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker.
Zyxel NWA110AX firmware versions prior to 6.50(ABTG.0)C0 are affected by CVE-2022-45854.
The severity of CVE-2022-45854 is medium with a CVSS score of 4.3.
An attacker can exploit CVE-2022-45854 by intercepting the MAC address of the vulnerable AP and sending crafted VLAN frames to cause a temporary denial-of-service (DoS) on the LAN.
To fix CVE-2022-45854, update your Zyxel NWA110AX firmware to version 6.50(ABTG.0)C0 or later.