First published: Mon May 01 2023(Updated: )
A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Nbg-418n Firmware | <=1.00\(aarp.13\)c0 | |
ZyXEL NBG-418N | =v2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22921 is high with a score of 7.5.
CVE-2023-22921 is a cross-site scripting (XSS) vulnerability that could allow a remote authenticated attacker to store malicious scripts using the web management interface, resulting in denial-of-service (DoS) conditions.
Yes, the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 are affected by CVE-2023-22921.
An attacker with administrator privileges can exploit CVE-2023-22921 by storing malicious scripts in the web management interface parameter.
You can find more information about CVE-2023-22921 in the Zyxel Security Advisory for Multiple Vulnerabilities in NBG-418N V2 Home Router: [link](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nbg-418n-v2-home-router)