First published: Mon Apr 24 2023(Updated: )
A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in denial-of-service (DoS) conditions on an affected device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel USG Flex 100 firmware | >=4.50<=5.35 | |
Zyxel USG Flex 100 firmware | ||
Zyxel USG FLEX 100w firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 100w firmware | ||
Zyxel USG Flex 200HP Firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50(W) series firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 50w | ||
Zyxel USG FLEX 50w | >=4.50<=5.35 | |
Zyxel USG FLEX 50(W) series firmware | ||
Zyxel USG FLEX 500 | >=4.50<=5.35 | |
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 700 firmware | ||
Zyxel VPN100 | >=4.50<=5.35 | |
Zyxel Zywall VPN100 | ||
Zyxel VPN1000 Firmware | >=4.50<=5.35 | |
Zyxel VPN1000 Firmware | ||
Zyxel Zywall VPN 300 Firmware | >=4.50<=5.35 | |
Zyxel Zywall VPN300 | ||
Zyxel Zywall VPN 50 Firmware | >=4.50<=5.35 | |
Zyxel VPN50 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-22913.
The severity of CVE-2023-22913 is high with a severity score of 8.1.
The affected software is Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35.
A remote authenticated attacker can exploit CVE-2023-22913 through a post-authentication command injection vulnerability in the 'account_operator.cgi' CGI program of Zyxel USG FLEX series firmware.
Yes, there is a fix available. It is recommended to update the firmware of affected devices to versions higher than 5.35.