CVE-2024-11253: OS Command Injection
A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11253?
CVE-2024-11253 is classified as a high severity vulnerability due to its ability to allow authenticated attackers to execute OS commands.
How do I fix CVE-2024-11253?
To fix CVE-2024-11253, upgrade the firmware of the Zyxel VMG8825-T50K to the latest version beyond V5.50(ABOM.8.5)C0.
Who is affected by CVE-2024-11253?
CVE-2024-11253 affects any device running the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier.
What type of vulnerability is CVE-2024-11253?
CVE-2024-11253 is a post-authentication command injection vulnerability.
Can CVE-2024-11253 be exploited remotely?
CVE-2024-11253 requires authenticated access, meaning it cannot be exploited remotely by unauthorized users.