Vulnerabilities > CVE-2023-28770 - Information Exposure Through Discrepancy vulnerability in Zyxel Dx5401-B0 Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
zyxel
CWE-203

Summary

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

Vulnerable Configurations

Part Description Count
OS
Zyxel
1
Hardware
Zyxel
1

Common Weakness Enumeration (CWE)