Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-02T11:15:09
Updated: 2024-08-04T15:12:08.714Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-24355
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-02T12:15:10.550
Modified: 2024-11-21T05:14:39.337
Link: CVE-2020-24355
Redhat
No data.