Описание
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
Ссылки
- Vendor Advisory
- URL Repurposed
- URL Repurposed
- Vendor Advisory
- Vendor Advisory
- URL Repurposed
- URL Repurposed
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:h:zyxel:p-335wt_router:*:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00447
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
почти 4 года назад
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
EPSS
Процентиль: 63%
0.00447
Низкий
7.5 High
CVSS2
Дефекты
CWE-264