CVE-2024-1575: Medium severity zyxel wbe660s firmware vulnerability
Published Jul 23, 2024
·Updated
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
Affected Software
41 affected components
Zyxel WBE660S<=6.70(ACGG.3)
All of the following
Zyxel NWA50AX firmware<7.00\(abyw.1\)
Zyxel NWA50AX
All of the following
Zyxel Nwa50ax-pro Firmware<7.00\(acge.1\)
Zyxel Nwa50ax-pro
All of the following
Zyxel Nwa55axe Firmware<7.00\(abzl.1\)
Zyxel Nwa55axe
All of the following
Zyxel Nwa90ax Firmware<7.00\(accv.1\)
Zyxel Nwa90ax
All of the following
Zyxel Nwa90ax-pro Firmware<7.00\(acgf.1\)
Zyxel Nwa90ax-pro
All of the following
Zyxel NWA110AX firmware<7.00\(abtg.1\)
Zyxel NWA110AX
All of the following
Zyxel Nwa210ax Firmware<7.00\(abtd.1\)
Zyxel Nwa210ax
All of the following
Zyxel Nwa220ax-6e Firmware<7.00\(acco.1\)
Zyxel Nwa220ax-6e
All of the following
Zyxel NWA1123ACv3 firmware<6.70\(abvt.4\)
Zyxel NWA1123ACv3
All of the following
Zyxel WAC500 firmware<6.70\(abvs.4\)
Zyxel WAC500
All of the following
Zyxel Wac500h Firmware<6.70\(abwa.4\)
Zyxel Wac500h
All of the following
Zyxel WAX300H firmware<7.00\(achf.1\)
Zyxel WAX300H
All of the following
Zyxel WAX510D firmware<7.00\(abtf.1\)
Zyxel WAX510D
All of the following
Zyxel Wax610d Firmware<7.00\(abte.1\)
Zyxel Wax610d
All of the following
Zyxel Wax620d-6e Firmware<7.00\(accn.1\)
Zyxel Wax620d-6e
All of the following
Zyxel Wax630s Firmware<7.00\(abzd.1\)
Zyxel Wax630s
All of the following
Zyxel Wax640s-6e Firmware<7.00\(accm.1\)
Zyxel Wax640s-6e
All of the following
Zyxel Wax650s Firmware<7.00\(abrm.1\)
Zyxel Wax650s
All of the following
Zyxel WAX655E firmware<7.00\(acdo.1\)
Zyxel WAX655E
All of the following
Zyxel WBE660S firmware<7.00\(acgg.1\)
Zyxel WBE660S
Event History
Jul 23, 2024
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1575?
CVE-2024-1575 is classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-1575?
To fix CVE-2024-1575, update the Zyxel WBE660S firmware to version 7.00(ACGG.1) or later.
3
What type of devices are affected by CVE-2024-1575?
CVE-2024-1575 affects the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier.
4
Can an unauthenticated user exploit CVE-2024-1575?
No, CVE-2024-1575 requires an authenticated user to exploit the privilege escalation vulnerability.
5
What could an attacker do by exploiting CVE-2024-1575?
By exploiting CVE-2024-1575, an attacker could escalate privileges and download sensitive configuration files from the affected device.