6.5

CVE-2023-22918

A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.

Data is provided by the National Vulnerability Database (NVD)
ZyxelAtp200 Firmware Version >= 4.32 < 5.36
   ZyxelAtp200 Version-
ZyxelAtp100 Firmware Version >= 4.32 < 5.36
   ZyxelAtp100 Version-
ZyxelAtp700 Firmware Version >= 4.32 < 5.36
   ZyxelAtp700 Version-
ZyxelAtp500 Firmware Version >= 4.32 < 5.36
   ZyxelAtp500 Version-
ZyxelAtp100w Firmware Version >= 4.32 < 5.36
   ZyxelAtp100w Version-
ZyxelAtp800 Firmware Version >= 4.32 < 5.36
   ZyxelAtp800 Version-
ZyxelUsg Flex 100 Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 50 Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 200 Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 500 Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 700 Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 100w Firmware Version >= 4.50 < 5.36
   ZyxelUsg Flex 100w Version-
ZyxelUsg 20w-vpn Firmware Version >= 4.16 < 5.36
   ZyxelUsg 20w-vpn Version-
ZyxelUsg Flex 50w Firmware Version >= 4.16 < 5.36
   ZyxelUsg Flex 50w Version-
ZyxelUsg20-vpn Firmware Version >= 4.30 < 5.36
   ZyxelUsg20-vpn Version-
ZyxelVpn100 Firmware Version >= 4.30 < 5.36
   ZyxelVpn100 Version-
ZyxelVpn1000 Firmware Version >= 4.30 < 5.36
   ZyxelVpn1000 Version-
ZyxelVpn300 Firmware Version >= 4.30 < 5.36
   ZyxelVpn300 Version-
ZyxelVpn50 Firmware Version >= 4.30 < 5.36
   ZyxelVpn50 Version-
ZyxelNap203 Firmware Version <= 6.28\(abfa.0\)
   ZyxelNap203 Version-
ZyxelNap303 Firmware Version <= 6.28\(abex.0\)
   ZyxelNap303 Version-
ZyxelNap353 Firmware Version <= 6.28\(abey.0\)
   ZyxelNap353 Version-
ZyxelNwa110ax Firmware Version <= 6.50\(abtg.2\)
   ZyxelNwa110ax Version-
ZyxelNwa1123-ac Hd Firmware Version <= 6.25\(abin.9\)
   ZyxelNwa1123-ac Hd Version-
ZyxelNwa1123-ac-pro Firmware Version <= 6.28\(abhd.0\)
   ZyxelNwa1123-ac-pro Version-
ZyxelNwa1123acv3 Firmware Version <= 6.50\(abvt.0\)
   ZyxelNwa1123acv3 Version-
ZyxelNwa210ax Firmware Version <= 6.50\(abtd.2\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version <= 6.50\(acco.2\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa50ax Firmware Version <= 6.55\(acge.1\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax-pro Firmware Version <= 6.50\(acge.0\)
   ZyxelNwa50ax-pro Version-
ZyxelNwa5123-ac Hd Firmware Version <= 6.25\(abim.9\)
   ZyxelNwa5123-ac Hd Version-
ZyxelNwa55axe Firmware Version <= 6.29\(abzl.1\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version <= 6.29\(accv.1\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax-pro Firmware Version <= 6.50\(acgf.0\)
   ZyxelNwa90ax-pro Version-
ZyxelWac500 Firmware Version <= 6.50\(abvs.0\)
   ZyxelWac500 Version-
ZyxelWac500h Firmware Version <= 6.50\(abwa.0\)
   ZyxelWac500h Version-
ZyxelWac5302d-sv2 Firmware Version <= 6.25\(abvz.9\)
   ZyxelWac5302d-sv2 Version-
ZyxelWac6103d-i Firmware Version <= 6.28\(aaxh.0\)
   ZyxelWac6103d-i Version-
ZyxelWac6303d-s Firmware Version <= 6.25\(abgl.9\)
   ZyxelWac6303d-s Version-
ZyxelWac6502d-e Firmware Version <= 6.28\(aasd.0\)
   ZyxelWac6502d-e Version-
ZyxelWac6502d-s Firmware Version <= 6.28\(aase.0\)
   ZyxelWac6502d-s Version-
ZyxelWac6503d-s Firmware Version <= 6.28\(aasf.0\)
   ZyxelWac6503d-s Version-
ZyxelWac6552d-s Firmware Version <= 6.28\(abio.0\)
   ZyxelWac6552d-s Version-
ZyxelWac6553d-e Firmware Version <= 6.28\(aasg.0\)
   ZyxelWac6553d-e Version-
ZyxelWax510d Firmware Version <= 6.50\(abtf.2\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version <= 6.50\(abte.2\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version <= 6.50\(accn.2\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version <= 6.50\(abzd.2\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version <= 6.50\(accm.2\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version <= 6.50\(abrm.2\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version <= 6.50\(acdo.2\)
   ZyxelWax655e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.402
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security@zyxel.com.tw 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.