A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Zyxel
Subscribe
|
Usg Flex 100
Subscribe
Usg Flex 100 Firmware
Subscribe
Usg Flex 100w
Subscribe
Usg Flex 100w Firmware
Subscribe
Usg Flex 200
Subscribe
Usg Flex 200 Firmware
Subscribe
Usg Flex 50
Subscribe
Usg Flex 500
Subscribe
Usg Flex 500 Firmware
Subscribe
Usg Flex 50 Firmware
Subscribe
Usg Flex 50w
Subscribe
Usg Flex 50w Firmware
Subscribe
Usg Flex 700
Subscribe
Usg Flex 700 Firmware
Subscribe
Vpn100
Subscribe
Vpn1000
Subscribe
Vpn1000 Firmware
Subscribe
Vpn100 Firmware
Subscribe
Vpn300
Subscribe
Vpn300 Firmware
Subscribe
Vpn50
Subscribe
Vpn50 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27016 | A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2025-02-12T16:22:16.191Z
Reserved: 2023-01-10T00:00:00.000Z
Link: CVE-2023-22914
Updated: 2024-08-02T10:20:31.461Z
Status : Modified
Published: 2023-04-24T17:15:09.627
Modified: 2024-11-21T07:45:38.337
Link: CVE-2023-22914
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD