CVE-2023-33013: OS Command Injection
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-33013?
CVE-2023-33013 is a post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0.
How severe is CVE-2023-33013?
CVE-2023-33013 is considered as a high severity vulnerability with a severity score of 8.8.
How does CVE-2023-33013 affect Zyxel NBG6604 firmware?
CVE-2023-33013 allows an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Is Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 affected?
Yes, Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 is affected by CVE-2023-33013.
How can I fix CVE-2023-33013?
To fix CVE-2023-33013, it is recommended to update Zyxel NBG6604 firmware to the latest version provided by Zyxel.