cbcvebase.
CVE-2023-34139
published 2023-07-17

CVE-2023-34139: A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series…

high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.

Affected

17 ranges
VendorProductVersion rangeFixed in
zyxelusg_2200-vpn_firmware>= 4.20 < 5.375.37
zyxelusg_flex_100_firmware>= 4.50 < 5.375.37
zyxelusg_flex_100w_firmware>= 4.50 < 5.375.37
zyxelusg_flex_200_firmware>= 4.50 < 5.375.37
zyxelusg_flex_500_firmware>= 4.50 < 5.375.37
zyxelusg_flex_50_firmware>= 4.50 < 5.375.37
zyxelusg_flex_50w_firmware>= 4.50 < 5.375.37
zyxelusg_flex_700_firmware>= 4.50 < 5.375.37
zyxelusg_flex_series_firmware
zyxelvpn_series_firmware
zyxelzywall_vpn100_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn2s_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn300_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn50_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_100_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_300_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_50_firmware>= 4.20 < 5.375.37