First published: Mon Jul 17 2023(Updated: )
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.
Credit: security@zyxel.com.tw security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Usg 2200-vpn Firmware | >=4.20<5.37 | |
Zyxel Usg 2200-vpn | ||
Zyxel Usg Flex 100 Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 100 | ||
Zyxel Usg Flex 100w Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 100w | ||
Zyxel Usg Flex 200 Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 200 | ||
Zyxel Usg Flex 50 Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 50 | ||
Zyxel Usg Flex 500 Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 500 | ||
Zyxel Usg Flex 50w Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 50w | ||
Zyxel Usg Flex 700 Firmware | >=4.50<5.37 | |
Zyxel Usg Flex 700 | ||
Zyxel Zywall Vpn100 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn100 | ||
Zyxel Zywall Vpn2s Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn2s | ||
Zyxel Zywall Vpn300 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn300 | ||
Zyxel Zywall Vpn50 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn50 | ||
Zyxel Zywall Vpn 100 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn 100 | ||
Zyxel Zywall Vpn 300 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn 300 | ||
Zyxel Zywall Vpn 50 Firmware | >=4.20<5.37 | |
Zyxel Zywall Vpn 50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-34139.
The severity of CVE-2023-34139 is high.
Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2 are affected.
An unauthenticated, LAN-based attacker can exploit CVE-2023-34139 by executing OS commands on an affected device.
Yes, users are advised to upgrade their firmware to version 5.37 or above to mitigate the vulnerability.