Vulnerability Description
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Usg 2200-Vpn Firmware | >= 4.20, < 5.37 |
| Zyxel | Usg 2200-Vpn | - |
| Zyxel | Usg Flex 100 Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 100 | - |
| Zyxel | Usg Flex 100W Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 100W | - |
| Zyxel | Usg Flex 200 Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 200 | - |
| Zyxel | Usg Flex 50 Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 50 | - |
| Zyxel | Usg Flex 500 Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 500 | - |
| Zyxel | Usg Flex 50W Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 50W | - |
| Zyxel | Usg Flex 700 Firmware | >= 4.50, < 5.37 |
| Zyxel | Usg Flex 700 | - |
| Zyxel | Zywall Vpn100 Firmware | >= 4.20, < 5.37 |
| Zyxel | Zywall Vpn100 | - |
| Zyxel | Zywall Vpn2S Firmware | >= 4.20, < 5.37 |
| Zyxel | Zywall Vpn2S | - |
Related Weaknesses (CWE)
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
FAQ
What is CVE-2023-34139?
CVE-2023-34139 is a vulnerability with a CVSS score of 8.8 (HIGH). A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patc...
How severe is CVE-2023-34139?
CVE-2023-34139 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34139?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Usg 2200-Vpn Firmware, Zyxel Usg 2200-Vpn, Zyxel Usg Flex 100 Firmware, Zyxel Usg Flex 100, Zyxel Usg Flex 100W Firmware.