CVE-2020-24355
Summary
| CVE | CVE-2020-24355 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-02 12:15:00 UTC |
| Updated | 2020-09-11 16:17:00 UTC |
| Description | Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zyxel | Vmg5313-b30b | - | All | All | All |
| Hardware | Zyxel | Vmg5313-b30b | - | All | All | All |
| Operating System | Zyxel | Vmg5313-b30b Firmware | All | All | All | All |
| Operating System | Zyxel | Vmg5313-b30b Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories | Zyxel | MISC | www.zyxel.com | Vendor Advisory |
| In 2070 or so | MISC | blog.somegeneric.ninja | Exploit, Third Party Advisory |
| In 2070 or so | MISC | blog.somegeneric.ninja | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.