8.8

CVE-2024-12398

An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelNwa50ax Firmware Version < 7.10\(abyw.1\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax Pro Firmware Version < 7.10\(acge.1\)
   ZyxelNwa50ax Pro Version-
ZyxelNwa55axe Firmware Version < 7.10\(abzl.1\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version < 7.10\(accv.1\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax Pro Firmware Version < 7.10\(acgf.1\)
   ZyxelNwa90ax Pro Version-
ZyxelNwa110ax Firmware Version < 7.10\(abtg.1\)
   ZyxelNwa110ax Version-
ZyxelNwa130be Firmware Version < 7.10\(acil.1\)
   ZyxelNwa130be Version-
ZyxelNwa210ax Firmware Version < 7.10\(abtd.1\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version < 7.10\(acco.1\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa1123acv3 Firmware Version < 6.70\(abvt.6\)
   ZyxelNwa1123acv3 Version-
ZyxelWac500 Firmware Version < 6.70\(abvs.6\)
   ZyxelWac500 Version-
ZyxelWac500h Firmware Version < 6.70\(abwa.6\)
   ZyxelWac500h Version-
ZyxelWax300h Firmware Version < 7.10\(achf.1\)
   ZyxelWax300h Version-
ZyxelWax510d Firmware Version < 7.10\(abtf.1\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version < 7.10\(abte.1\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version < 7.10\(accn.1\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version < 7.10\(abzd.1\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version < 7.10\(accm.1\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version < 7.10\(abrm.1\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version < 7.10\(acdo.1\)
   ZyxelWax655e Version-
ZyxelWbe530 Firmware Version < 7.10\(acle.1\)
   ZyxelWbe530 Version-
ZyxelWbe660s Firmware Version < 7.00\(acgg.1\)
   ZyxelWbe660s Version-
ZyxelUsg Lite 60ax Firmware Version < 2.10\(acip.0\)
   ZyxelUsg Lite 60ax Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.