Description
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Published: 2024-12-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-50361 A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
History

Tue, 21 Jan 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel emg6726-b10a
Zyxel vmg3927-b50b
Zyxel vmg4005-b50a
Zyxel vmg4005-b50b
Zyxel vmg4005-b60a
Zyxel vmg4927-b50a
CPEs cpe:2.3:h:zyxel:emg6726-b10a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg3927-b50b:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4005-b50a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4005-b50b:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4005-b60a:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:vmg4927-b50a:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:emg6726-b10a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg3927-b50b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b50b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b60a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zyxel emg6726-b10a
Zyxel vmg3927-b50b
Zyxel vmg4005-b50a
Zyxel vmg4005-b50b
Zyxel vmg4005-b60a
Zyxel vmg4927-b50a

Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel emg6726-b10a Firmware
Zyxel vmg3927-b50b Firmware
Zyxel vmg4005-b50a Firmware
Zyxel vmg4005-b50b Firmware
Zyxel vmg4005-b60a Firmware
Zyxel vmg4927-b50a Firmware
CPEs cpe:2.3:o:zyxel:emg6726-b10a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg3927-b50b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b50a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b50b_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4005-b60a_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:vmg4927-b50a_firmware:-:*:*:*:*:*:*:*
Vendors & Products Zyxel
Zyxel emg6726-b10a Firmware
Zyxel vmg3927-b50b Firmware
Zyxel vmg4005-b50a Firmware
Zyxel vmg4005-b50b Firmware
Zyxel vmg4005-b60a Firmware
Zyxel vmg4927-b50a Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 01:45:00 +0000

Type Values Removed Values Added
Description A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zyxel Emg6726-b10a Emg6726-b10a Firmware Vmg3927-b50b Vmg3927-b50b Firmware Vmg4005-b50a Vmg4005-b50a Firmware Vmg4005-b50b Vmg4005-b50b Firmware Vmg4005-b60a Vmg4005-b60a Firmware Vmg4927-b50a Vmg4927-b50a Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-12-06T04:55:23.779Z

Reserved: 2024-09-26T09:34:37.485Z

Link: CVE-2024-9200

cve-icon Vulnrichment

Updated: 2024-12-03T16:46:41.804Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-03T02:15:17.913

Modified: 2025-01-21T21:13:29.700

Link: CVE-2024-9200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses