Vulnerability CVE-2023-22913


Published: 2023-04-24

Description:
A post-authentication command injection vulnerability in the ??account_operator.cgi? CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in denial-of-service (DoS) conditions on an affected device.

 References:
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps

Copyright 2026, cxsecurity.com

 

Back to Top