CVE-2023-22913: Command Injection
A post-authentication command injection vulnerability in the “accountoperator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in denial-of-service (DoS) conditions on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-22913.
What is the severity of CVE-2023-22913?
The severity of CVE-2023-22913 is high with a severity score of 8.1.
What is the affected software of CVE-2023-22913?
The affected software is Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35.
How can a remote authenticated attacker exploit CVE-2023-22913?
A remote authenticated attacker can exploit CVE-2023-22913 through a post-authentication command injection vulnerability in the 'account_operator.cgi' CGI program of Zyxel USG FLEX series firmware.
Is there a fix available for CVE-2023-22913?
Yes, there is a fix available. It is recommended to update the firmware of affected devices to versions higher than 5.35.