First published: Tue Sep 03 2024(Updated: )
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware versions from V5.00 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted compressed language file via FTP.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Zyxel ZLD Firmware | >=5.00<5.39 | |
Any of | ||
Zyxel ATP100 Firmware | ||
Zyxel ATP100W Firmware | ||
Zyxel Zywall ATP200 | ||
Zyxel ATP500 Firmware | ||
Zyxel ATP700 Firmware | ||
Zyxel Zywall ATP800 Firmware | ||
All of | ||
Zyxel ZLD Firmware | >=5.00<5.39 | |
Any of | ||
Zyxel USG Flex 100 firmware | ||
Zyxel USG FLEX 100ax firmware | ||
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50w | ||
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX 50(W) series firmware | ||
Zyxel USG FLEX 700 firmware | ||
All of | ||
Zyxel ZLD Firmware | >=5.00<5.39 | |
Zyxel USG20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42059 is classified as a critical vulnerability due to its potential for command injection post-authentication.
To fix CVE-2024-42059, update your Zyxel devices to firmware version 5.39 or later.
CVE-2024-42059 affects Zyxel ATP series, USG FLEX series, and USG20(W)-VPN series firmware from versions 5.00 to 5.38.
CVE-2024-42059 is a post-authentication command injection vulnerability allowing an attacker to execute arbitrary commands.
No specific workaround is recommended; the best practice is to upgrade to the latest firmware version.