9.8
CVE-2022-38546
- EPSS 0.11%
- Veröffentlicht 21.12.2022 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:16:39
- Quelle security@zyxel.com.tw
- CVE-Watchlists
- Unerledigt
A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zyxel ≫ Nbg7510 Firmware Version <= 1.00\(abzy.2\)c0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| security@zyxel.com.tw | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.