Vulnerability Description
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Lte3202-M437 Firmware | 1.00\(abwf.1\)c0 |
| Zyxel | Lte3202-M437 | - |
| Zyxel | Lte3316-M604 Firmware | 2.00\(abmp.6\)c0 |
| Zyxel | Lte3316-M604 | - |
Related Weaknesses (CWE)
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
FAQ
What is CVE-2023-22920?
CVE-2023-22920 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker c...
How severe is CVE-2023-22920?
CVE-2023-22920 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-22920?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Lte3202-M437 Firmware, Zyxel Lte3202-M437, Zyxel Lte3316-M604 Firmware, Zyxel Lte3316-M604.