Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24355

Опубликовано: 02 сент. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zyxel:vmg5313-b30b_firmware:*:*:*:*:*:*:*:*
Версия до 5.13\(abcj.6\)b3_1127 (включая)
cpe:2.3:h:zyxel:vmg5313-b30b:-:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00367
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-732

Связанные уязвимости

github
больше 3 лет назад

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.

EPSS

Процентиль: 58%
0.00367
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-732