8.1
CVSSv3

CVE-2023-22913

Published: 24/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 up to and including 5.35, and VPN series firmware versions 4.30 up to and including 5.35, which could allow a remote authenticated malicious user to modify device configuration data, resulting in denial-of-service (DoS) conditions on an affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel usg_flex_100_firmware

zyxel usg_flex_100w_firmware

zyxel usg_flex_200_firmware

zyxel usg_flex_50_firmware

zyxel usg_flex_50w_firmware

zyxel usg_flex_500_firmware

zyxel usg_flex_700_firmware

zyxel vpn100_firmware

zyxel vpn1000_firmware

zyxel vpn300_firmware

zyxel vpn50_firmware