Zyxel security advisory for CGI vulnerability of LTE
Zyxel security advisory for CGI vulnerability of LTE
CVE: CVE-2020-28899
Summary
Zyxel has released LTE router patches addressing a common gateway interface (CGI) vulnerability. Users are advised to install the applicable firmware updates for optimal protection.
What is the vulnerability?
A CGI script vulnerability arising from the lack of an authentication request was identified in some Zyxel LTE routers.
What versions are vulnerable—and what should you do?
After a thorough investigation, we’ve identified the vulnerable LTE routers that are within their warranty and support period and released firmware patches to address the issue, as shown in the table below.
Please note that the table does NOT include customized models for internet service providers (ISPs). For ISP customers, please contact your Zyxel representative for further details. For users who purchased the listed devices on their own, please download the new firmware from following links:
Affected model | Patch availability |
---|---|
LTE4506-M606 | V1.00(ABDO.6)C0 |
LTE7460-M608 | V1.00(ABFR.5)C0 |
WAH7706 | V1.00(ABBC.12)C0 |
Got a question or a tipoff?
Please contact your local service rep for further information or assistance. If you’ve found a vulnerability, we want to work with you to fix it—contact security@zyxel.com.tw and we’ll get right back to you.
Acknowledgment
Thanks to Vincent ERUDEL for reporting the issue to us.
Revision history
2021-3-5: Initial release
2021-3-23: Updated the patch firmware version of WAH7706
Categories
- All Categories
- 414 Beta Program
- 2.3K Nebula
- 132 Nebula Ideas
- 92 Nebula Status and Incidents
- 5.4K Security
- 181 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 37 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight