First published: Mon Apr 24 2023(Updated: )
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Usg Flex 100 Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 100 | ||
Zyxel Usg Flex 100w Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 100w | ||
Zyxel Usg Flex 200 Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 200 | ||
Zyxel Usg Flex 50 Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 50 | ||
Zyxel Usg Flex 50w Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 50w | ||
Zyxel Usg Flex 500 Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 500 | ||
Zyxel Usg Flex 700 Firmware | >=4.50<=5.35 | |
Zyxel Usg Flex 700 | ||
Zyxel Vpn100 Firmware | >=4.50<=5.35 | |
Zyxel Vpn100 | ||
Zyxel Multiple Network-Attached Storage (NAS) Devices | >=4.50<=5.35 | |
Zyxel Multiple Network-Attached Storage (NAS) Devices | ||
Zyxel Vpn300 Firmware | >=4.50<=5.35 | |
Zyxel Vpn300 | ||
Zyxel Vpn50 Firmware | >=4.50<=5.35 | |
Zyxel Vpn50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the Zyxel USG FLEX series firmware is CVE-2023-22914.
The severity of CVE-2023-22914 is high with a CVSS score of 7.2.
Zyxel USG FLEX series firmware versions 4.50 through 5.35 are affected by CVE-2023-22914.
A remote authenticated attacker with administrator privileges can exploit CVE-2023-22914 to execute unauthorized OS commands.
Update the affected Zyxel USG FLEX series firmware versions to a patched version provided by Zyxel.