VYPR
High severity8.0NVD Advisory· Published Jul 17, 2023· Updated Jun 17, 2026

CVE-2023-34138

CVE-2023-34138

Description

A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.60 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.60 through 5.36 Patch 2, and VPN series firmware versions 4.60 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device if the attacker could trick an authorized administrator to add their IP address to the list of trusted RADIUS clients in advance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

31

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.