Aller au contenu

Fiche vulnérabilité

CVE-2023-34139 : faille élevée zyxel usg 2200-vpn firmware (CVSS 8.8)

Description

A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 juil. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • zyxel usg 2200-vpn firmware
  • zyxel usg flex 100 firmware
  • zyxel usg flex 100w firmware
  • zyxel usg flex 200 firmware
  • zyxel usg flex 50 firmware
  • zyxel usg flex 500 firmware
  • zyxel usg flex 50w firmware
  • zyxel usg flex 700 firmware
  • zyxel zywall vpn100 firmware
  • zyxel zywall vpn2s firmware
  • zyxel zywall vpn300 firmware
  • zyxel zywall vpn50 firmware
  • zyxel zywall vpn 100 firmware
  • zyxel zywall vpn 300 firmware
  • zyxel zywall vpn 50 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE