CVE-2024-1575

The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
ZyxelCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
zyxelnwa50ax_firmware
𝑥
< 7.00\(abyw.1\)
zyxelnwa50ax-pro_firmware
𝑥
< 7.00\(acge.1\)
zyxelnwa55axe_firmware
𝑥
< 7.00\(abzl.1\)
zyxelnwa90ax_firmware
𝑥
< 7.00\(accv.1\)
zyxelnwa90ax-pro_firmware
𝑥
< 7.00\(acgf.1\)
zyxelnwa110ax_firmware
𝑥
< 7.00\(abtg.1\)
zyxelnwa210ax_firmware
𝑥
< 7.00\(abtd.1\)
zyxelnwa220ax-6e_firmware
𝑥
< 7.00\(acco.1\)
zyxelnwa1123acv3_firmware
𝑥
< 6.70\(abvt.4\)
zyxelwac500_firmware
𝑥
< 6.70\(abvs.4\)
zyxelwac500h_firmware
𝑥
< 6.70\(abwa.4\)
zyxelwax300h_firmware
𝑥
< 7.00\(achf.1\)
zyxelwax510d_firmware
𝑥
< 7.00\(abtf.1\)
zyxelwax610d_firmware
𝑥
< 7.00\(abte.1\)
zyxelwax620d-6e_firmware
𝑥
< 7.00\(accn.1\)
zyxelwax630s_firmware
𝑥
< 7.00\(abzd.1\)
zyxelwax640s-6e_firmware
𝑥
< 7.00\(accm.1\)
zyxelwax650s_firmware
𝑥
< 7.00\(abrm.1\)
zyxelwax655e_firmware
𝑥
< 7.00\(acdo.1\)
zyxelwbe660s_firmware
𝑥
< 7.00\(acgg.1\)
𝑥
= Vulnerable software versions