Overview
ZyXEL Wireless N300 NetUSB Router NBG-419N running firmware version 1.00(BFQ.6)C0, and possibly earlier versions, is susceptible to multiple vulnerabilities. Other device models that use similar firmware may also be vulnerable.
Description
ZyXEL Wireless N300 NetUSB Router NBG-419N running firmware version 1.00(BFQ.6)C0, and possibly earlier versions, has been reported to contain multiple vulnerabilities. CWE-425: Direct Request - CVE-2014-0353 |
Impact
A remote unauthenticated attacker on the local area network may be able to inject arbitrary commands or run arbitrary code. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workarounds. |
Restrict Access |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
ZyXEL | Affected | 23 Jan 2014 | 10 Mar 2014 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 7.9 | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 5.7 | E:U/RL:W/RC:UC |
Environmental | 5.7 | CDP:ND/TD:H/CR:ND/IR:ND/AR:ND |
References
- http://www.zyxel.com/us/en/products_services/nbg_419n_v2.shtml?t=p
- https://cwe.mitre.org/data/definitions/425.html
- https://cwe.mitre.org/data/definitions/259.html
- https://cwe.mitre.org/data/definitions/121.html
- https://cwe.mitre.org/data/definitions/78.html
Credit
Thanks to the reporter who wishes to remain anonymous for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2014-0353 CVE-2014-0354 CVE-2014-0355 CVE-2014-0356
- Date Public: 10 3월 2014
- Date First Published: 11 4월 2014
- Date Last Updated: 11 4월 2014
- Document Revision: 19
'취약점 정보1' 카테고리의 다른 글
PivotX 2.3.8 contains multiple vulnerabilities (0) | 2014.04.13 |
---|---|
Amtelco miSecureMessages app lacks authentication (0) | 2014.04.13 |
Fortinet FortiADC contains a cross-site scripting vulnerability (0) | 2014.04.13 |
Interested in a Heartbleed Challenge? (0) | 2014.04.13 |
Jetpack 2.9.3: Critical Security Update (0) | 2014.04.13 |