First published: Tue Jul 23 2024(Updated: )
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel WBE660S firmware | <=6.70(ACGG.3) | |
All of | ||
Zyxel NWA50AX-Pro firmware | <7.00\(abyw.1\) | |
Zyxel NWA50AX-PRO | ||
All of | ||
Zyxel NWA50AX Pro | <7.00\(acge.1\) | |
Zyxel NWA50AX-Pro firmware | ||
All of | ||
Zyxel NWA55AXE Firmware | <7.00\(abzl.1\) | |
Zyxel NWA55AXE Firmware | ||
All of | ||
Zyxel NWA90AX Pro Firmware | <7.00\(accv.1\) | |
Zyxel NWA90AX Firmware | ||
All of | ||
Zyxel NWA90AX Pro Firmware | <7.00\(acgf.1\) | |
Zyxel NWA90AX-PRO Firmware | ||
All of | ||
Zyxel NWA110AX firmware | <7.00\(abtg.1\) | |
Zyxel NWA110AX | ||
All of | ||
Zyxel NWA210AX | <7.00\(abtd.1\) | |
Zyxel NWA210AX Firmware | ||
All of | ||
Zyxel nwa220ax-6e firmware | <7.00\(acco.1\) | |
Zyxel NWA220AX-6E | ||
All of | ||
Zyxel NWA1123-AC PRO firmware | <6.70\(abvt.4\) | |
Zyxel NWA1123-AC PRO firmware | ||
All of | ||
Zyxel WAC500H Firmware | <6.70\(abvs.4\) | |
Zyxel WAC500 firmware | ||
All of | ||
Zyxel WAC500H Firmware | <6.70\(abwa.4\) | |
Zyxel WAC500H Firmware | ||
All of | ||
Zyxel WAX300H | <7.00\(achf.1\) | |
Zyxel WAX300H firmware | ||
All of | ||
Zyxel WAX510D firmware | <7.00\(abtf.1\) | |
Zyxel WAX510D firmware | ||
All of | ||
Zyxel WAX610D | <7.00\(abte.1\) | |
Zyxel WAX610D Firmware | ||
All of | ||
Zyxel WAX620D-6E | <7.00\(accn.1\) | |
Zyxel WAX620D-6E Firmware | ||
All of | ||
Zyxel WAX630S Firmware | <7.00\(abzd.1\) | |
Zyxel WAX630S Firmware | ||
All of | ||
Zyxel WAX640S-6E | <7.00\(accm.1\) | |
Zyxel WAX640S-6E Firmware | ||
All of | ||
Zyxel wax650s firmware | <7.00\(abrm.1\) | |
Zyxel WAX650S | ||
All of | ||
Zyxel WAX655E Firmware | <7.00\(acdo.1\) | |
Zyxel WAX655E Firmware | ||
All of | ||
Zyxel WBE660S firmware | <7.00\(acgg.1\) | |
Zyxel WBE660S firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1575 is classified as a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-1575, update the Zyxel WBE660S firmware to version 7.00(ACGG.1) or later.
CVE-2024-1575 affects the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier.
No, CVE-2024-1575 requires an authenticated user to exploit the privilege escalation vulnerability.
By exploiting CVE-2024-1575, an attacker could escalate privileges and download sensitive configuration files from the affected device.