Zyxel security advisory for improper privilege management vulnerability in APs
CVE: CVE-2024-1575
Summary
Zyxel has released patches addressing an improper privilege management vulnerability in some access point (AP) versions. Users are advised to install the patches for optimal protection.
What is the vulnerability?
The improper privilege management vulnerability in some Zyxel AP versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
What versions are vulnerable—and what should you do?
After a thorough investigation,we’ve identified the vulnerable AP versions that are within their vulnerability support period and released patches to address the vulnerability, as shown in the table below.
|
Affected model
|
|
Affected version
|
|
Patch availability
|
|
---|---|---|---|---|---|---|
| ||||||
|
NWA50AX
|
|
6.29(ABYW.4) and earlier
|
|
|
|
| ||||||
|
NWA50AX-PRO
|
|
6.65(ACGE.1) and earlier
|
|
|
|
| ||||||
|
NWA55AXE
|
|
6.29(ABZL.4) and earlier
|
|
|
|
| ||||||
|
NWA90AX
|
|
6.29(ACCV.4) and earlier
|
|
|
|
| ||||||
|
NWA90AX-PRO
|
|
6.65(ACGF.1) and earlier
|
|
|
|
| ||||||
|
NWA110AX
|
|
6.70(ABTG.2) and earlier
|
|
|
|
| ||||||
|
NWA210AX
|
|
6.70(ABTD.2) and earlier
|
|
|
|
| ||||||
|
NWA220AX-6E
|
|
6.70(ACCO.1) and earlier
|
|
|
|
| ||||||
|
NWA1123ACv3
|
|
6.70(ABVT.1) and earlier
|
|
|
|
| ||||||
|
WAC500
|
|
6.70(ABVS.1) and earlier
|
|
|
|
| ||||||
|
WAC500H
|
|
6.70(ABWA.1) and earlier
|
|
|
|
| ||||||
|
WAX300H
|
|
6.70(ACHF.1) and earlier
|
|
|
|
| ||||||
|
WAX510D
|
|
6.70(ABTF.2) and earlier
|
|
|
|
| ||||||
|
WAX610D
|
|
6.70(ABTE.2) and earlier
|
|
|
|
| ||||||
|
WAX620D-6E
|
|
6.70(ACCN.1) and earlier
|
|
|
|
| ||||||
|
WAX630S
|
|
6.70(ABZD.2) and earlier
|
|
|
|
| ||||||
|
WAX640S-6E
|
|
6.70(ACCM.1) and earlier
|
|
|
|
| ||||||
|
WAX650S
|
|
6.70(ABRM.2) and earlier
|
|
|
|
| ||||||
|
WAX655E
|
|
6.70(ACDO.1) and earlier
|
|
|
|
| ||||||
|
WBE660S
|
|
6.70(ACGG.3) and earlier
|
|
|
|
Got a question?
Please contact your local service rep or visit Zyxel’s Community for further information or assistance.
Acknowledgment
Thanks to Alessandro Sgreccia from HackerHood for reporting the issue to us.
Revision history
2024-7-23:Initial release.
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight