Vulnerability Description
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Nbg-418N V2 Firmware | 1.00\(aarp.9\)c0 |
| Zyxel | Nbg-418N V2 | - |
Related Weaknesses (CWE)
References
- https://github.com/d0x0/Zyxel-NBG-418N-v2/blob/master/CVE-2019-17354Third Party Advisory
- https://www.zyxel.com/us/en/Product
- https://github.com/d0x0/Zyxel-NBG-418N-v2/blob/master/CVE-2019-17354Third Party Advisory
- https://www.zyxel.com/us/en/Product
FAQ
What is CVE-2019-17354?
CVE-2019-17354 is a vulnerability with a CVSS score of 9.4 (CRITICAL). wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leve...
How severe is CVE-2019-17354?
CVE-2019-17354 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17354?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Nbg-418N V2 Firmware, Zyxel Nbg-418N V2.