#VU34062 Improper access control in ZyXEL Communications Corp. products - CVE-2020-13365
Published: August 5, 2020
Zyxel NAS 326
NAS520
NAS540
NAS542
ZyXEL Communications Corp.
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in a CGI script for the web application. A remote authenticated attacker can start a Telnet or SSH service and generate a password for the "NsaRescueAngel" user account with root privileges.