VYPR
Unrated severityNVD Advisory· Published Jul 17, 2023· Updated Oct 29, 2024

CVE-2023-34139

CVE-2023-34139

Description

A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2023-34139 is a command injection in the Free Time WiFi hotspot feature of Zyxel firewalls, allowing an unauthenticated, LAN-based attacker to execute OS commands on affected devices.

Vulnerability

A command injection vulnerability exists in the Free Time WiFi hotspot feature of Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2 [1]. The vulnerability allows an unauthenticated, LAN-based attacker to execute arbitrary OS commands on the affected device via the hotspot feature, without requiring any special configuration or authentication [1].

Exploitation

An attacker must be on the same local network as the vulnerable device [1]. No authentication is required, and the attacker can directly send crafted input to the Free Time WiFi hotspot functionality to trigger command injection [1]. The steps involve leveraging the hotspot feature to inject commands into the system, which are then executed by the device's operating system [1].

Impact

Successful exploitation allows an unauthenticated, LAN-based attacker to execute arbitrary OS commands on the affected device [1]. This could lead to full compromise of the firewall, including data exfiltration, further network penetration, and potential denial of service [1]. The attack does not require any user interaction or prior access privileges [1].

Mitigation

Zyxel has released patched firmware versions for the affected series [1]. Users are advised to update to the latest firmware versions available from Zyxel's security advisory to mitigate the vulnerability [1]. No workarounds have been provided, and the vulnerability is not known to be listed in the CISA KEV [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.