Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28770


The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.


Published

2023-04-27T09:15:09.850

Last Modified

2025-01-31T19:15:13.130

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-200
  • Type: Secondary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel dx5401-b0_firmware < 5.17\(abyo.1\)c0 Yes
Hardware zyxel dx5401-b0 - No

References