CVE-2023-34138: Command Injection
A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.60 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.60 through 5.36 Patch 2, and VPN series firmware versions 4.60 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device if the attacker could trick an authorized administrator to add their IP address to the list of trusted RADIUS clients in advance.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2023-34138.
What is the severity level of CVE-2023-34138?
The severity level of CVE-2023-34138 is high.
What is the affected software for CVE-2023-34138?
The affected software for CVE-2023-34138 includes Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, and USG FLEX 50(W) series firmware versions 4.60 through 5.36 Patch 2.
How can I fix CVE-2023-34138?
To fix CVE-2023-34138, it is recommended to update to a firmware version higher than 5.37 or apply the necessary patches provided by Zyxel.
Where can I find more information about CVE-2023-34138?
More information about CVE-2023-34138 can be found in the Zyxel Security Advisory for Multiple Vulnerabilities in Firewalls and WLAN Controllers.