CVE-2024-12398: High severity Zyxel WBE530 vulnerability
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12398?
The severity of CVE-2024-12398 is considered high due to its ability to allow privilege escalation for authenticated users.
How do I fix CVE-2024-12398?
To mitigate CVE-2024-12398, update the firmware of affected Zyxel devices to the latest version that is not vulnerable.
Which Zyxel devices are affected by CVE-2024-12398?
CVE-2024-12398 affects Zyxel WBE530 firmware versions up to 7.00(ACLE.3) and WBE660S firmware versions up to 6.70(ACGG.2).
Can CVE-2024-12398 be exploited remotely?
CVE-2024-12398 requires authenticated access, meaning an attacker must have some level of user access to exploit this vulnerability.
What are the potential consequences of CVE-2024-12398?
Exploitation of CVE-2024-12398 may lead to unauthorized access to administrative functions and control over the affected network devices.