CVE-2024-7203: OS Command Injection
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device by executing a crafted CLI command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7203?
CVE-2024-7203 is rated as a high severity vulnerability due to the potential for code execution by authenticated attackers.
How do I fix CVE-2024-7203?
To mitigate CVE-2024-7203, update the Zyxel ATP series and USG FLEX series firmware to versions after V5.38.
Who is affected by CVE-2024-7203?
CVE-2024-7203 affects Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38.
What kind of attacks can CVE-2024-7203 enable?
CVE-2024-7203 may allow an authenticated attacker with administrator privileges to execute operating system commands on vulnerable devices.
Is remote access possible through CVE-2024-7203?
CVE-2024-7203 does not enable remote access; it requires authentication with administrator privileges.