VYPR
Unrated severityNVD Advisory· Published Nov 28, 2023· Updated Aug 2, 2024

CVE-2023-37925

CVE-2023-37925

Description

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access system files on an affected device.

Affected products

9
  • Zyxel/ATP seriescpe-rescue
    Range: versions 4.32 through 5.37
  • Zyxel/NWA50AX firmwarev5
    Range: 6.29(ABYW.2)
  • Range: versions 4.16 through 5.37
  • Zyxel/USG FLEX seriescpe-rescue2 versions
    versions 4.16 through 5.37+ 1 more
    • (no CPE)range: versions 4.16 through 5.37
    • (no CPE)range: versions 4.50 through 5.37
  • Zyxel/VPN seriescpe-rescue
    Range: versions 4.30 through 5.37
  • Zyxel/WAC500 firmwarev5
    Range: 6.65(ABVS.1)
  • Zyxel/WAX300H firmwarev5
    Range: 6.60(ACHF.1)
  • Zyxel/WBE660S firmwarev5
    Range: 6.65(ACGG.1)

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.