cbcvebase.
CVE-2023-33013
published 2023-08-14

CVE-2023-33013: A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.

Affected

2 ranges
VendorProductVersion rangeFixed in
zyxelnbg6604_firmware
zyxelnbg6604_firmware