Zyxel USG FLEX H
cpe:2.3:h:zyxel:usg_flex:*:*:*:*:*:*:*, +16 more
- >= V1.20, <= V1.31
A vulnerability has been identified in the recovery function of the USG FLEX H series firewalls, specifically in the uOS firmware versions through 1.31. This vulnerability involves improper privilege management, which could enable an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on the affected device.
Exploitation of this vulnerability could lead to unauthorized privilege escalation on the affected device, allowing the attacker to gain elevated rights and potentially misuse them for malicious purposes.
Users are advised to update to the latest firmware version, uOS V1.32, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.