NA

CVE-2023-28770

Published: 27/04/2023 Updated: 10/05/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated malicious user to read the system files and to retrieve the password of the supervisor from the encrypted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel dx5401-b0_firmware

Exploits

This Metasploit module exploits multiple vulnerabilities in the zhttpd binary (/bin/zhttpd) and zcmd binary (/bin/zcmd) It is present on more than 40 Zyxel routers and CPE devices The remote code execution vulnerability can be exploited by chaining the local file disclosure vulnerability in the zhttpd binary that allows an unauthenticated attacke ...