First published: Tue Dec 03 2024(Updated: )
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel VMG4005-B50A firmware | <=V5.15(ABQA.2.2)C0 | |
All of | ||
Zyxel EMG6726-B10A | <5.13\(abnp.8\)c1 | |
Zyxel EMG6726-B10A Firmware | ||
All of | ||
Zyxel VMG3927-B50B | <5.13\(ably.9\)c1 | |
Zyxel VMG3927-B50B Firmware | ||
All of | ||
Zyxel VMG4005-B50A firmware | <5.15\(abqa.2.3\)c0 | |
Zyxel VMG4005-B50A firmware | ||
All of | ||
Zyxel VMG4005-B60A | <5.15\(abqa.2.3\)c0 | |
Zyxel VMG4005-B60A | ||
All of | ||
Zyxel VMG4005-B50B | <5.13\(abrl.5.2\)c0 | |
Zyxel VMG4005-B50B Firmware | ||
All of | ||
Zyxel Vmg4927-b50a Firmware | <5.13\(ably.9\)c1 | |
Zyxel VMG4927-B50A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9200 has a high severity rating due to its potential to allow authenticated attackers to execute OS commands.
To fix CVE-2024-9200, upgrade your Zyxel VMG4005-B50A firmware to version V5.15(ABQA.2.3)C0 or later.
CVE-2024-9200 affects users of Zyxel VMG4005-B50A firmware versions up to and including V5.15(ABQA.2.2)C0.
CVE-2024-9200 is a post-authentication command injection vulnerability.
The potential impact of CVE-2024-9200 includes unauthorized execution of commands on the affected device.