漏洞描述 Zyxel USG/ZyWALL系列固件版本4.20至4.70、USGFLEX系列固件版本4.50至5.20、ATP系列固件版本4.32至5.20,VPN系列固件版本4.3至5.20以及NSG系列固件版本V1.20至V1.33Patch 4的CGI程序中存在身份验证绕过漏洞,攻击者可以绕过web身份验证并获得设备的管理访问权限。
相关漏洞推荐 POC CVE-2018-19326: Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion POC CVE-2019-12581: Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting POC CVE-2019-12583: Zyxel ZyWall UAG/USG - Account Creation Access POC CVE-2019-9955: Zyxel - Cross-Site Scripting POC CVE-2020-29583: ZyXel USG - Hardcoded Credentials POC CVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code Execution POC CVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass POC CVE-2021-46387: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting POC CVE-2022-0342: Zyxel - Authentication Bypass POC CVE-2022-30525: Zyxel Firewall - OS Command Injection POC CVE-2024-29972: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account POC CVE-2024-29973: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection POC CVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass