First published: Mon Aug 14 2023(Updated: )
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Credit: security@zyxel.com.tw security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel NBG6604 firmware | =1.01\(abir.1\)c0 | |
Zyxel NBG6604 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33013 is a post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0.
CVE-2023-33013 is considered as a high severity vulnerability with a severity score of 8.8.
CVE-2023-33013 allows an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Yes, Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 is affected by CVE-2023-33013.
To fix CVE-2023-33013, it is recommended to update Zyxel NBG6604 firmware to the latest version provided by Zyxel.