# N/A
## 概述
Zyxel DX3300-T0 固件中存在一个基于身份验证后的命令注入漏洞,位于 `priv` 参数中。
## 影响版本
- 固件版本:5.50(ABVY.6.3)C0 及更早版本
## 细节
攻击者在通过身份验证后,可通过精心构造的请求对 `priv` 参数注入恶意操作系统命令。
## 影响
成功利用此漏洞的认证用户可在目标设备上执行任意操作系统命令,可能导致设备被完全控制。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: Security Advisories | Zyxel Networks -- 🔗来源链接
标签:vendor-advisory
神龙速读:
- 漏洞关键信息:
- **CVE ID** | **Title** | **Last Updated**
- CVE-2025-6599, CVE-2025-8693 | Zyxel security advisory for uncontrolled resource consumption and command injection vulnerabilities in certain 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, Security Routers, and Wireless Extenders | November 18, 2025
- CVE-2025-8078, CVE-2025-9133 | Zyxel security advisory for post-authentication command injection and missing authorization vulnerabilities in ZLD firewalls | October 21, 2025
- CVE-2025-7673 | Zyxel security advisory for remote code execution and denial-of-service vulnerabilities of CPE | July 16, 2025
- CVE-2025-6265 | Zyxel security advisory for path traversal vulnerability in APs | July 15, 2025
- CVE-2025-1731, CVE-2025-1732 | Zyxel security advisory for incorrect permission assignment and improper privilege management vulnerabilities in USG FLEX H series firewalls | April 22, 2025
- CVE-2024-11253, CVE-2024-12009, CVE-2024-12010 | Zyxel security advisory for post-authentication command injection vulnerabilities in certain DSL/Ethernet CPE, fiber ONT, and WiFi extender devices | March 11, 2025
- CVE-2024-40890, CVE-2024-40891, CVE-2025-0890 | Zyxel security advisory for command injection and insecure default credentials vulnerabilities in certain legacy DSL CPE | February 4, 2025
- CVE-2024-12398 | Zyxel security advisory for improper privilege management vulnerability in APs and security router devices | January 14, 2025
- CVE-2024-8748, CVE-2024-9197, CVE-2024-9200 | Zyxel security advisory for buffer overflow and post-authentication command injection vulnerabilities in some 4G LTE/5G NR CPE, DSL/Ethernet CPE, fiber ONTs, and WiFi extenders | December 3, 2024
- CVE-2024-11667 | Zyxel security advisory: protecting against recent firewall threats | November 27, 2024
暂无评论