CRITICAL · 9.4

CVE-2019-17354

wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leve...

Vulnerability Description

wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.

CVSS Score

9.4

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelNbg-418N V2 Firmware1.00\(aarp.9\)c0
ZyxelNbg-418N V2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17354?

CVE-2019-17354 is a vulnerability with a CVSS score of 9.4 (CRITICAL). wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leve...

How severe is CVE-2019-17354?

CVE-2019-17354 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-17354?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nbg-418N V2 Firmware, Zyxel Nbg-418N V2.