CVE-2023-4957: Authentication Bypass on Zebra ZTC

Published Oct 11, 2023
·
Updated

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as the printer, to change the username and password for the Web Page by sending a specially crafted POST request to the setvarsResults.cgi file. For this vulnerability to be exploitable, the printers protected mode must be disabled.

Affected Software

4 affected components
All of the following
Zebra Zt410 Firmware
Zebra ZT410
Zebra Zt410 Firmware
Zebra ZT410

Remediation

Information

Zebra Printers running Link-OS v6.0 and later have a protected mode that protects the printer from this vulnerability. Activating this mode disables unauthorized changes and locks the current configuration until an administrator authorizes updates. By default, the secure mode is disabled as it is necessary to generate a password first. NOTE: the ZT410 industrial printer was discontinued on Oct 1st, 2020. The service and Support discontinuation dates are in September and December 2025 depending on region. Further information regarding security settings and best practices, including “Protected Mode”, can be found in the references. UPDATE: The vulnerability has been fixed by Zebra. The updated firmware version is Link-OS v7.3 which was released March 2025. The currently released version is Link-OS v7.4 which includes the fix that was released in the previous version.

Event History

Oct 11, 2023
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID of this authentication bypass vulnerability?

The vulnerability ID of this authentication bypass vulnerability is CVE-2023-4957.

2

What is the affected software for this vulnerability?

The affected software for this vulnerability is Zebra Zt410 Firmware.

3

How severe is CVE-2023-4957?

CVE-2023-4957 has a severity rating of medium with a score of 4.3.

4

How can an attacker exploit this vulnerability?

An attacker can exploit this vulnerability by sending a specially crafted POST request to the Zebra ZTC ZT410-203dpi ZPL printer in the same network, allowing them to change the username and password for the Web Page.

5

Is there a fix available for this vulnerability?

Please refer to the vendor's security advisory for information on available fixes for CVE-2023-4957.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203