A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Metrics
Affected Vendors & Products
History
Tue, 03 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zyxel
Zyxel emg6726-b10a Firmware Zyxel vmg3927-b50b Firmware Zyxel vmg4005-b50a Firmware Zyxel vmg4005-b50b Firmware Zyxel vmg4005-b60a Firmware Zyxel vmg4927-b50a Firmware |
|
CPEs | cpe:2.3:o:zyxel:emg6726-b10a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg3927-b50b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4005-b50a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4005-b50b_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4005-b60a_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:vmg4927-b50a_firmware:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Zyxel
Zyxel emg6726-b10a Firmware Zyxel vmg3927-b50b Firmware Zyxel vmg4005-b50a Firmware Zyxel vmg4005-b50b Firmware Zyxel vmg4005-b60a Firmware Zyxel vmg4927-b50a Firmware |
|
Metrics |
ssvc
|
Tue, 03 Dec 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Zyxel
Published: 2024-12-03T01:33:47.398Z
Updated: 2024-12-06T04:55:23.779Z
Reserved: 2024-09-26T09:34:37.485Z
Link: CVE-2024-9200
Vulnrichment
Updated: 2024-12-03T16:46:41.804Z
NVD
Status : Received
Published: 2024-12-03T02:15:17.913
Modified: 2024-12-03T02:15:17.913
Link: CVE-2024-9200
Redhat
No data.