Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22918


A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.


Published

2023-04-24T18:15:09.027

Last Modified

2024-11-21T07:45:38.940

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-359
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel atp200_firmware < 5.36 Yes
Hardware zyxel atp200 - No
Operating System zyxel atp100_firmware < 5.36 Yes
Hardware zyxel atp100 - No
Operating System zyxel atp700_firmware < 5.36 Yes
Hardware zyxel atp700 - No
Operating System zyxel atp500_firmware < 5.36 Yes
Hardware zyxel atp500 - No
Operating System zyxel atp100w_firmware < 5.36 Yes
Hardware zyxel atp100w - No
Operating System zyxel atp800_firmware < 5.36 Yes
Hardware zyxel atp800 - No
Operating System zyxel usg_flex_100_firmware < 5.36 Yes
Hardware zyxel usg_flex_100 - No
Operating System zyxel usg_flex_50_firmware < 5.36 Yes
Hardware zyxel usg_flex_50 - No
Operating System zyxel usg_flex_200_firmware < 5.36 Yes
Hardware zyxel usg_flex_200 - No
Operating System zyxel usg_flex_500_firmware < 5.36 Yes
Hardware zyxel usg_flex_500 - No
Operating System zyxel usg_flex_700_firmware < 5.36 Yes
Hardware zyxel usg_flex_700 - No
Operating System zyxel usg_flex_100w_firmware < 5.36 Yes
Hardware zyxel usg_flex_100w - No
Operating System zyxel usg_20w-vpn_firmware < 5.36 Yes
Hardware zyxel usg_20w-vpn - No
Operating System zyxel usg_flex_50w_firmware < 5.36 Yes
Hardware zyxel usg_flex_50w - No
Operating System zyxel usg20-vpn_firmware < 5.36 Yes
Hardware zyxel usg20-vpn - No
Operating System zyxel vpn100_firmware < 5.36 Yes
Hardware zyxel vpn100 - No
Operating System zyxel vpn1000_firmware < 5.36 Yes
Hardware zyxel vpn1000 - No
Operating System zyxel vpn300_firmware < 5.36 Yes
Hardware zyxel vpn300 - No
Operating System zyxel vpn50_firmware < 5.36 Yes
Hardware zyxel vpn50 - No
Operating System zyxel nap203_firmware ≤ 6.28\(abfa.0\) Yes
Hardware zyxel nap203 - No
Operating System zyxel nap303_firmware ≤ 6.28\(abex.0\) Yes
Hardware zyxel nap303 - No
Operating System zyxel nap353_firmware ≤ 6.28\(abey.0\) Yes
Hardware zyxel nap353 - No
Operating System zyxel nwa110ax_firmware ≤ 6.50\(abtg.2\) Yes
Hardware zyxel nwa110ax - No
Operating System zyxel nwa1123-ac_hd_firmware ≤ 6.25\(abin.9\) Yes
Hardware zyxel nwa1123-ac_hd - No
Operating System zyxel nwa1123-ac-pro_firmware ≤ 6.28\(abhd.0\) Yes
Hardware zyxel nwa1123-ac-pro - No
Operating System zyxel nwa1123acv3_firmware ≤ 6.50\(abvt.0\) Yes
Hardware zyxel nwa1123acv3 - No
Operating System zyxel nwa210ax_firmware ≤ 6.50\(abtd.2\) Yes
Hardware zyxel nwa210ax - No
Operating System zyxel nwa220ax-6e_firmware ≤ 6.50\(acco.2\) Yes
Hardware zyxel nwa220ax-6e - No
Operating System zyxel nwa50ax_firmware ≤ 6.55\(acge.1\) Yes
Hardware zyxel nwa50ax - No
Operating System zyxel nwa50ax-pro_firmware ≤ 6.50\(acge.0\) Yes
Hardware zyxel nwa50ax-pro - No
Operating System zyxel nwa5123-ac_hd_firmware ≤ 6.25\(abim.9\) Yes
Hardware zyxel nwa5123-ac_hd - No
Operating System zyxel nwa55axe_firmware ≤ 6.29\(abzl.1\) Yes
Hardware zyxel nwa55axe - No
Operating System zyxel nwa90ax_firmware ≤ 6.29\(accv.1\) Yes
Hardware zyxel nwa90ax - No
Operating System zyxel nwa90ax-pro_firmware ≤ 6.50\(acgf.0\) Yes
Hardware zyxel nwa90ax-pro - No
Operating System zyxel wac500_firmware ≤ 6.50\(abvs.0\) Yes
Hardware zyxel wac500 - No
Operating System zyxel wac500h_firmware ≤ 6.50\(abwa.0\) Yes
Hardware zyxel wac500h - No
Operating System zyxel wac5302d-sv2_firmware ≤ 6.25\(abvz.9\) Yes
Hardware zyxel wac5302d-sv2 - No
Operating System zyxel wac6103d-i_firmware ≤ 6.28\(aaxh.0\) Yes
Hardware zyxel wac6103d-i - No
Operating System zyxel wac6303d-s_firmware ≤ 6.25\(abgl.9\) Yes
Hardware zyxel wac6303d-s - No
Operating System zyxel wac6502d-e_firmware ≤ 6.28\(aasd.0\) Yes
Hardware zyxel wac6502d-e - No
Operating System zyxel wac6502d-s_firmware ≤ 6.28\(aase.0\) Yes
Hardware zyxel wac6502d-s - No
Operating System zyxel wac6503d-s_firmware ≤ 6.28\(aasf.0\) Yes
Hardware zyxel wac6503d-s - No
Operating System zyxel wac6552d-s_firmware ≤ 6.28\(abio.0\) Yes
Hardware zyxel wac6552d-s - No
Operating System zyxel wac6553d-e_firmware ≤ 6.28\(aasg.0\) Yes
Hardware zyxel wac6553d-e - No
Operating System zyxel wax510d_firmware ≤ 6.50\(abtf.2\) Yes
Hardware zyxel wax510d - No
Operating System zyxel wax610d_firmware ≤ 6.50\(abte.2\) Yes
Hardware zyxel wax610d - No
Operating System zyxel wax620d-6e_firmware ≤ 6.50\(accn.2\) Yes
Hardware zyxel wax620d-6e - No
Operating System zyxel wax630s_firmware ≤ 6.50\(abzd.2\) Yes
Hardware zyxel wax630s - No
Operating System zyxel wax640s-6e_firmware ≤ 6.50\(accm.2\) Yes
Hardware zyxel wax640s-6e - No
Operating System zyxel wax650s_firmware ≤ 6.50\(abrm.2\) Yes
Hardware zyxel wax650s - No
Operating System zyxel wax655e_firmware ≤ 6.50\(acdo.2\) Yes
Hardware zyxel wax655e - No

References