7.2
CVSSv3

CVE-2023-22914

Published: 24/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 up to and including 5.35, and VPN series firmware versions 4.30 up to and including 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel usg_flex_100_firmware

zyxel usg_flex_100w_firmware

zyxel usg_flex_200_firmware

zyxel usg_flex_50_firmware

zyxel usg_flex_50w_firmware

zyxel usg_flex_500_firmware

zyxel usg_flex_700_firmware

zyxel vpn100_firmware

zyxel vpn1000_firmware

zyxel vpn300_firmware

zyxel vpn50_firmware