6.5

CVE-2024-1575

The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.

Data is provided by the National Vulnerability Database (NVD)
ZyxelNwa50ax Firmware Version < 7.00\(abyw.1\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax-pro Firmware Version < 7.00\(acge.1\)
   ZyxelNwa50ax-pro Version-
ZyxelNwa55axe Firmware Version < 7.00\(abzl.1\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version < 7.00\(accv.1\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax-pro Firmware Version < 7.00\(acgf.1\)
   ZyxelNwa90ax-pro Version-
ZyxelNwa110ax Firmware Version < 7.00\(abtg.1\)
   ZyxelNwa110ax Version-
ZyxelNwa210ax Firmware Version < 7.00\(abtd.1\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version < 7.00\(acco.1\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa1123acv3 Firmware Version < 6.70\(abvt.4\)
   ZyxelNwa1123acv3 Version-
ZyxelWac500 Firmware Version < 6.70\(abvs.4\)
   ZyxelWac500 Version-
ZyxelWac500h Firmware Version < 6.70\(abwa.4\)
   ZyxelWac500h Version-
ZyxelWax300h Firmware Version < 7.00\(achf.1\)
   ZyxelWax300h Version-
ZyxelWax510d Firmware Version < 7.00\(abtf.1\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version < 7.00\(abte.1\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version < 7.00\(accn.1\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version < 7.00\(abzd.1\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version < 7.00\(accm.1\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version < 7.00\(abrm.1\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version < 7.00\(acdo.1\)
   ZyxelWax655e Version-
ZyxelWbe660s Firmware Version < 7.00\(acgg.1\)
   ZyxelWbe660s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.413
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security@zyxel.com.tw 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.