Learn about CVE-2020-24355 affecting Zyxel VMG5313-B30B routers, allowing users to create new accounts with elevated privileges. Find mitigation steps and firmware update recommendations here.
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions allowing users to create new users with elevated privileges.
Understanding CVE-2020-24355
This CVE identifies a security vulnerability in Zyxel VMG5313-B30B routers that enables users to manipulate JSON data during account creation to gain elevated privileges.
What is CVE-2020-24355?
The vulnerability in Zyxel VMG5313-B30B routers allows regular and other users to create new users with elevated privileges by modifying the "FirstIndex" field in the JSON data during account creation.
The Impact of CVE-2020-24355
The insecure permissions in affected firmware versions can lead to unauthorized users gaining elevated privileges, posing a significant security risk to the network and data.
Technical Details of CVE-2020-24355
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by this vulnerability.
Vulnerability Description
The vulnerability allows users to create new accounts with elevated privileges by manipulating JSON data during account creation.
Affected Systems and Versions
Exploitation Mechanism
Users exploit the vulnerability by changing the "FirstIndex" field in the JSON data during account creation, granting themselves elevated privileges.
Mitigation and Prevention
It is crucial to take immediate steps to mitigate the risks posed by CVE-2020-24355.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates