Overview
ZyXEL Wireless N300 NetUSB Router NBG-419N running firmware version 1.00(BFQ.6)C0, and possibly earlier versions, is susceptible to multiple vulnerabilities. Other device models that use similar firmware may also be vulnerable.
Description
ZyXEL Wireless N300 NetUSB Router NBG-419N running firmware version 1.00(BFQ.6)C0, and possibly earlier versions, has been reported to contain multiple vulnerabilities. CWE-425: Direct Request - CVE-2014-0353 |
Impact
A remote unauthenticated attacker on the local area network may be able to inject arbitrary commands or run arbitrary code. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workarounds. |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.9 | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 5.7 | E:U/RL:W/RC:UC |
Environmental | 5.7 | CDP:ND/TD:H/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to the reporter who wishes to remain anonymous for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2014-0353, CVE-2014-0354, CVE-2014-0355, CVE-2014-0356 |
Date Public: | 2014-03-10 |
Date First Published: | 2014-04-11 |
Date Last Updated: | 2014-04-16 14:41 UTC |
Document Revision: | 23 |