CVE-2023-22918
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
Affected (51)
Products: Zyxel: Atp200 Firmware, Atp100 Firmware, Atp700 Firmware, Atp500 Firmware, Atp100w Firmware, Atp800 Firmware, Usg Flex 100 Firmware, Usg Flex 50 Firmware, Usg Flex 200 Firmware, Usg Flex 500 Firmware, Usg Flex 700 Firmware, Usg Flex 100w Firmware, Usg 20w Vpn Firmware, Usg Flex 50w Firmware, Usg20 Vpn Firmware, Vpn100 Firmware, Vpn1000 Firmware, Vpn300 Firmware, Vpn50 Firmware, Nap203 Firmware, Nap303 Firmware, Nap353 Firmware, Nwa110ax Firmware, Nwa1123 Ac Hd Firmware, Nwa1123 Ac Pro Firmware, Nwa1123acv3 Firmware, Nwa210ax Firmware, Nwa220ax 6e Firmware, Nwa50ax Firmware, Nwa50ax Pro Firmware, Nwa5123 Ac Hd Firmware, Nwa55axe Firmware, Nwa90ax Firmware, Nwa90ax Pro Firmware, Wac500 Firmware, Wac500h Firmware, Wac5302d Sv2 Firmware, Wac6103d I Firmware, Wac6303d S Firmware, Wac6502d E Firmware, Wac6502d S Firmware, Wac6503d S Firmware, Wac6552d S Firmware, Wac6553d E Firmware, Wax510d Firmware, Wax610d Firmware, Wax620d 6e Firmware, Wax630s Firmware, Wax640s 6e Firmware, Wax650s Firmware, Wax655e Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp100w | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.32 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp800 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 100 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 50 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 200 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 500 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 700 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.50 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 100w | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.16 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg 20w Vpn | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.16 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 50w | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.30 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg20 Vpn | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.30 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vpn100 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.30 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vpn1000 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.30 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vpn300 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.30 to 5.36 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vpn50 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(abfa.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nap203 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(abex.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nap303 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(abey.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nap353 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abtg.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa110ax | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.25\(abin.9\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa1123 Ac Hd | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(abhd.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa1123 Ac Pro | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abvt.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa1123acv3 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abtd.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa210ax | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(acco.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa220ax 6e | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.55\(acge.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa50ax | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(acge.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa50ax Pro | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.25\(abim.9\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa5123 Ac Hd | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.29\(abzl.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa55axe | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.29\(accv.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa90ax | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(acgf.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nwa90ax Pro | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abvs.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac500 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abwa.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac500h | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.25\(abvz.9\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac5302d Sv2 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(aaxh.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6103d I | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.25\(abgl.9\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6303d S | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(aasd.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6502d E | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(aase.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6502d S | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(aasf.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6503d S | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(abio.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6552d S | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.28\(aasg.0\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wac6553d E | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abtf.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax510d | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abte.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax610d | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(accn.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax620d 6e | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abzd.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax630s | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(accm.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax640s 6e | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(abrm.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax650s | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.50\(acdo.2\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Wax655e | All versions |
References (2)
Source: security@zyxel.com.tw
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.