Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37925


An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access system files on an affected device.


Published

2023-11-28T02:15:42.547

Last Modified

2024-11-21T08:12:29.060

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel zld ≤ 5.37 Yes
Hardware zyxel atp100 - No
Hardware zyxel atp100w - No
Hardware zyxel atp200 - No
Hardware zyxel atp500 - No
Hardware zyxel atp700 - No
Hardware zyxel atp800 - No
Operating System zyxel zld ≤ 5.37 Yes
Hardware zyxel usg_flex_100 - No
Hardware zyxel usg_flex_100w - No
Hardware zyxel usg_flex_200 - No
Hardware zyxel usg_flex_50 - No
Hardware zyxel usg_flex_500 - No
Hardware zyxel usg_flex_50w - No
Hardware zyxel usg_flex_700 - No
Operating System zyxel zld ≤ 5.37 Yes
Hardware zyxel usg_20w-vpn - No
Hardware zyxel vpn50w - No
Operating System zyxel zld ≤ 5.37 Yes
Hardware zyxel vpn100 - No
Hardware zyxel vpn1000 - No
Hardware zyxel vpn300 - No
Hardware zyxel vpn50 - No
Operating System zyxel nwa110ax_firmware < 6.70\(abtg.0\) Yes
Hardware zyxel nwa110ax - No
Operating System zyxel nwa1123acv3_firmware < 6.70\(abvt.0\) Yes
Hardware zyxel nwa1123acv3 - No
Operating System zyxel nwa210ax_firmware < 6.70\(abtd.0\) Yes
Hardware zyxel nwa210ax - No
Operating System zyxel nwa220ax-6e_firmware < 6.70\(acco.0\) Yes
Hardware zyxel nwa220ax-6e - No
Operating System zyxel nwa50ax_firmware < 6.80\(abyw.0\) Yes
Hardware zyxel nwa50ax - No
Operating System zyxel nwa50ax-pro_firmware < 6.80\(acge.0\) Yes
Hardware zyxel nwa50ax-pro - No
Operating System zyxel nwa55axe_firmware < 6.80\(abzl.0\) Yes
Hardware zyxel nwa55axe - No
Operating System zyxel nwa90ax_firmware < 6.80\(accv.0\) Yes
Hardware zyxel nwa90ax - No
Operating System zyxel nwa90ax-pro_firmware < 6.80\(acgf.0\) Yes
Hardware zyxel nwa90ax-pro - No
Operating System zyxel wac500_firmware < 6.70\(abvs.0\) Yes
Hardware zyxel wac500 - No
Operating System zyxel wac500h_firmware < 6.70\(abwa.0\) Yes
Hardware zyxel wac500h - No
Operating System zyxel wax510d_firmware < 6.70\(abtf.0\) Yes
Hardware zyxel wax510d - No
Operating System zyxel wax610d_firmware < 6.70\(abte.0\) Yes
Hardware zyxel wax610d - No
Operating System zyxel wax620d-6e_firmware < 6.70\(accn.0\) Yes
Hardware zyxel wax620d-6e - No
Operating System zyxel wax630s_firmware < 6.70\(abzd.0\) Yes
Hardware zyxel wax630s - No
Operating System zyxel wax640s-6e_firmware < 6.70\(accm.0\) Yes
Hardware zyxel wax640s-6e - No
Operating System zyxel wax650s_firmware < 6.70\(abrm.0\) Yes
Hardware zyxel wax650s - No
Operating System zyxel wax655e_firmware < 6.70\(acdo.0\) Yes
Hardware zyxel wax655e - No
Operating System zyxel wbe660s_firmware < 6.70\(acgg.0\) Yes
Hardware zyxel wbe660s - No

References