CVE-2023-6398

A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, 

USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1,

NWA50AX firmware versions through 6.29(ABYW.3), WAC500 firmware versions through 6.65(ABVS.1), WAX300H firmware versions through 6.60(ACHF.1), and WBE660S firmware versions through 6.65(ACGG.1) could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device via FTP.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ZyxelCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
zyxelatp100_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp100_firmware
5.37
zyxelatp100_firmware
5.37:patch1
zyxelatp100w_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp100w_firmware
5.37
zyxelatp100w_firmware
5.37:patch1
zyxelatp200_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp200_firmware
5.37
zyxelatp200_firmware
5.37:patch1
zyxelatp500_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp500_firmware
5.37
zyxelatp500_firmware
5.37:patch1
zyxelatp700_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp700_firmware
5.37
zyxelatp700_firmware
5.37:patch1
zyxelatp800_firmware
4.32 ≤
𝑥
< 5.37
zyxelatp800_firmware
5.37
zyxelatp800_firmware
5.37:patch1
zyxelusg_flex_100_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_100_firmware
5.37
zyxelusg_flex_100_firmware
5.37:patch1
zyxelusg_flex_100ax_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_100ax_firmware
5.37
zyxelusg_flex_100ax_firmware
5.37:patch1
zyxelusg_flex_100h_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_100h_firmware
5.37
zyxelusg_flex_100h_firmware
5.37:patch1
zyxelusg_flex_100w_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_100w_firmware
5.37
zyxelusg_flex_100w_firmware
5.37:patch1
zyxelusg_flex_200_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_200_firmware
5.37
zyxelusg_flex_200_firmware
5.37:patch1
zyxelusg_flex_200h_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_200h_firmware
5.37
zyxelusg_flex_200h_firmware
5.37:patch1
zyxelusg_flex_200hp_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_200hp_firmware
5.37
zyxelusg_flex_200hp_firmware
5.37:patch1
zyxelusg_flex_50_firmware
4.16 ≤
𝑥
< 5.37
zyxelusg_flex_50_firmware
5.37
zyxelusg_flex_50_firmware
5.37:patch1
zyxelusg_flex_500_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_500_firmware
5.37
zyxelusg_flex_500_firmware
5.37:patch1
zyxelusg_flex_500h_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_500h_firmware
5.37
zyxelusg_flex_500h_firmware
5.37:patch1
zyxelusg_flex_50w_firmware
4.16 ≤
𝑥
< 5.37
zyxelusg_flex_50w_firmware
5.37
zyxelusg_flex_50w_firmware
5.37:patch1
zyxelusg_flex_700_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_700_firmware
5.37
zyxelusg_flex_700_firmware
5.37:patch1
zyxelusg_flex_700h_firmware
4.50 ≤
𝑥
< 5.37
zyxelusg_flex_700h_firmware
5.37
zyxelusg_flex_700h_firmware
5.37:patch1
zyxelusg20-vpn_firmware
4.16 ≤
𝑥
< 5.37
zyxelusg20-vpn_firmware
5.37
zyxelusg20-vpn_firmware
5.37:patch1
zyxelusg20w-vpn_firmware
4.16 ≤
𝑥
< 5.37
zyxelusg20w-vpn_firmware
5.37
zyxelusg20w-vpn_firmware
5.37:patch1
zyxeluos
1.10
zyxeluos
1.10:patch1
zyxelnwa50ax_firmware
𝑥
< 6.29\(abyw.4\)
zyxelnwa55axe_firmware
𝑥
< 6.29\(abzl.4\)
zyxelnwa90ax_firmware
𝑥
< 6.29\(accv.4\)
zyxelnwa110ax_firmware
𝑥
< 6.70\(abtg.2\)
zyxelnwa210ax_firmware
𝑥
< 6.70\(abtd.2\)
zyxelnwa220ax-6e_firmware
𝑥
< 6.70\(acco.1\)
zyxelnwa1123acv3_firmware
𝑥
< 6.70\(abvt.1\)
zyxelwac500_firmware
𝑥
< 6.70\(abvs.1\)
zyxelwac500h_firmware
𝑥
< 6.70\(abwa.1\)
zyxelwax300h_firmware
𝑥
< 6.70\(achf.1\)
zyxelwax510d_firmware
𝑥
< 6.70\(abtf.2\)
zyxelwax610d_firmware
𝑥
< 6.70\(abte.2\)
zyxelwax620d-6e_firmware
𝑥
< 6.70\(accn.1\)
zyxelwax630s_firmware
𝑥
< 6.70\(abzd.2\)
zyxelwax640s-6e_firmware
𝑥
< 6.70\(accm.1\)
zyxelwax650s_firmware
𝑥
< 6.70\(abrm.2\)
zyxelwax655e_firmware
𝑥
< 6.70\(acdo.1\)
zyxelwbe660s_firmware
𝑥
< 6.70\(acgg.2\)
zyxelnwa50ax-pro_firmware
𝑥
< 6.80\(acge.0\)
zyxelnwa90ax-pro_firmware
𝑥
< 6.80\(acgf.0\)
𝑥
= Vulnerable software versions