cbcvebase.
CVE-2023-34139
published 2023-07-17

CVE-2023-34139: A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series…

PriorityP355high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.69%
48.7th percentile
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.

Affected

17 ranges
VendorProductVersion rangeFixed in
zyxelusg_2200-vpn_firmware>= 4.20 < 5.375.37
zyxelusg_flex_100_firmware>= 4.50 < 5.375.37
zyxelusg_flex_100w_firmware>= 4.50 < 5.375.37
zyxelusg_flex_200_firmware>= 4.50 < 5.375.37
zyxelusg_flex_500_firmware>= 4.50 < 5.375.37
zyxelusg_flex_50_firmware>= 4.50 < 5.375.37
zyxelusg_flex_50w_firmware>= 4.50 < 5.375.37
zyxelusg_flex_700_firmware>= 4.50 < 5.375.37
zyxelusg_flex_series_firmware
zyxelvpn_series_firmware
zyxelzywall_vpn100_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn2s_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn300_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn50_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_100_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_300_firmware>= 4.20 < 5.375.37
zyxelzywall_vpn_50_firmware>= 4.20 < 5.375.37
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.