CVE Feed

    Dashboard / CVE / CVE-2020-24355

    CVE-2020-24355

    Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.

    Published:Sep 2, 2020
    Last Modified:Nov 21, 2024
    EPS:Sep 2, 2020
    EPSS Score:0.00367
    CVSS Score:9.8

    Affected Products

    Vendor
    Zyxel
    Product
    Vmg5313-b30b
    Vendor
    Zyxel
    Product
    Vmg5313-b30b Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High