Improper access control in ZyXEL Communications Corp. products - CVE-2020-13365
Published: August 5, 2020
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in a CGI script for the web application. A remote authenticated attacker can start a Telnet or SSH service and generate a password for the "NsaRescueAngel" user account with root privileges.
Affected software
NAS520
NAS540
NAS542
How to mitigate CVE-2020-13365
NAS520 - update to V5.21(AASZ.5)C0
NAS540 - update to V5.21(AATB.6)C0
NAS542 - update to V5.21(ABAG.6)C0