An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
History

Tue, 14 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 02:00:00 +0000

Type Values Removed Values Added
Description An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published: 2025-01-14T01:39:04.348Z

Updated: 2025-01-14T15:26:24.681Z

Reserved: 2024-12-10T03:31:12.696Z

Link: CVE-2024-12398

cve-icon Vulnrichment

Updated: 2025-01-14T15:26:18.975Z

cve-icon NVD

Status : Received

Published: 2025-01-14T02:15:07.990

Modified: 2025-01-14T02:15:07.990

Link: CVE-2024-12398

cve-icon Redhat

No data.