| |
Vulnerability CVE-2023-22914
Published: 2023-04-24
| Description: |
A path traversal vulnerability in the ??account_print.cgi? CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the ??tmp? directory by uploading a crafted file if the hotspot function were enabled. |
References: |
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|