- Description
- An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
- Source
- security@zyxel.com.tw
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security@zyxel.com.tw
- CWE-269
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
#Vulnerability #CVE202412398 Zyxel Urges Patch Application for Privilege Escalation Vulnerability (CVE-2024-12398) https://t.co/xWtSG3ObiP
@Komodosec
7 Feb 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
4/9 @zyxel tackled a privilege escalation bug (CVE-2024-12398) in 23 models of APs & routers. Check your device model and update to secure your network! #ZyxelSecurity #NetworkSafety
@Eth1calHackrZ
18 Jan 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-12398 impacts Zyxel Devices #Zyxel #CVE-2024-12398 https://t.co/tOkc6MoaKi
@pravin_karthik
14 Jan 2025
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zyxel alerts users of a critical vulnerability (CVE-2024-12398) allowing privilege escalation on models like NWA50AX and WAC500. Patches available now! 🛡️ #Zyxel #FirmwareUpdate #USA #CybersecurityNews link: https://t.co/tNjtARy1QL https://t.co/WXyR7D2V0f
@TweetThreatNews
14 Jan 2025
22 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
The severity is increased for this new vulnerability affecting Zyxel WBE530 and WBE660S (CVE-2024-12398) https://t.co/yl5aH8IJ7X
@vuldb
14 Jan 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zyxel Urges Patch Application for Privilege Escalation Vulnerability (CVE-2024-12398) https://t.co/YGLn0olOca "With a CVSS score of 8.8, this vulnerability underscores the urgency for users to apply patches immediately to protect their systems from potential exploitation."
@catnap707
14 Jan 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Zyxel Urges Patch Application for Privilege Escalation Vulnerability (CVE-2024-12398) Protect your Zyxel access points and routers from CVE-2024-12398. Learn about the vulnerability and apply the necessary patches to safeguard your systems https://t.co/pS5yaa2WHD
@the_yellow_fall
14 Jan 2025
255 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-12398: HIGH] Vulnerability in Zyxel WBE530 & WBE660S firmware allows privileged escalation for authenticated users, making it possible to upload configuration files, posing cyber security risks.#cybersecurity,#vulnerability https://t.co/QzBvFn8eO0 https://t.co/R3Ewd
@CveFindCom
14 Jan 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa50ax_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4CDBEB22-3832-4C51-B811-8A2BF996D09E",
"versionEndExcluding": "7.10\\(abyw.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa50ax:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2806A3B3-8F13-4170-B284-8809E3502044"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa50ax_pro_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9719A4E4-DB57-4703-AC29-FD94CF89E7E0",
"versionEndExcluding": "7.10\\(acge.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa50ax_pro:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F36E7DCD-08BA-4FA1-9A8E-ADE956704132"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa55axe_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD6F3443-E169-4CA7-B18D-2DF68A507E59",
"versionEndExcluding": "7.10\\(abzl.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa55axe:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B7440976-5CB4-40BE-95C2-98EF4B888109"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa90ax_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7961037-D162-4BAA-948E-18BB25385117",
"versionEndExcluding": "7.10\\(accv.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa90ax:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3A903978-737E-4266-A670-BC94E32CAF96"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa90ax_pro_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EBC66E4-8643-47FE-80C0-14E53318C84E",
"versionEndExcluding": "7.10\\(acgf.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa90ax_pro:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "480A495A-A4C4-4696-B500-B6333C79A28B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa110ax_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E159E289-85E2-4A82-B0DF-309096479A81",
"versionEndExcluding": "7.10\\(abtg.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa110ax:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6A3F9232-F988-4428-9898-4F536123CE88"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa130be_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4360DF1-898A-4CCE-905D-05AE164195B5",
"versionEndExcluding": "7.10\\(acil.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa130be:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "782F9AB7-3464-4BFE-B502-B62CD51A8865"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa210ax_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF298D2B-3FCE-4974-9720-00266FE68D09",
"versionEndExcluding": "7.10\\(abtd.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa210ax:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1BB129F9-64D8-43C2-9366-51EBDF419F5F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa220ax-6e_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A290449D-A968-4E76-A3E0-58483D14CA34",
"versionEndExcluding": "7.10\\(acco.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa220ax-6e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6E03F755-424D-4248-9076-ED7BECEB94C5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nwa1123acv3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD3C70D2-3ABE-45D1-BAC1-F5378CA3B758",
"versionEndExcluding": "6.70\\(abvt.6\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nwa1123acv3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "36C13E7F-2186-4587-83E9-57B05A7147B7"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wac500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61033C21-7255-4BBC-A22E-E87FB4C92C88",
"versionEndExcluding": "6.70\\(abvs.6\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wac500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7C024551-F08F-4152-940D-1CF8BCD79613"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wac500h_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACC84162-28C7-4DA9-88C4-BFAE9315C805",
"versionEndExcluding": "6.70\\(abwa.6\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wac500h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1A1FD502-4F62-4C77-B3BC-E563B24F0067"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax300h_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91F75AB8-A165-4A09-B8F8-B63548E09887",
"versionEndExcluding": "7.10\\(achf.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax300h:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C3073565-BCDF-46EA-8FB0-E9BF402A5122"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax510d_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A34A2784-082B-4E26-8E1F-C395A7151DE5",
"versionEndExcluding": "7.10\\(abtf.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax510d:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2A37A0E9-D505-4376-AB0E-1C0FD7E53A55"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax610d_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE039840-2274-4E56-ABA5-EEF2932A3046",
"versionEndExcluding": "7.10\\(abte.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax610d:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3518DA0A-2C7B-4979-A457-0826C921B0F0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax620d-6e_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B410A50-3756-43BC-AAC3-3CCA65CD24EA",
"versionEndExcluding": "7.10\\(accn.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax620d-6e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2B4EBCC9-4FF9-41FC-9FFE-DBFAB239888B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax630s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75F74AE8-4CF4-4CDE-9CA0-1FB0E31D8DEB",
"versionEndExcluding": "7.10\\(abzd.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax630s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DC74AAF9-5206-4CEB-9023-6CD4F38AA623"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax640s-6e_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DFA7899-2BFE-4F0D-B18B-059C16A4742E",
"versionEndExcluding": "7.10\\(accm.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax640s-6e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "20E4E9A0-DF92-47B7-94D6-0867E3171E47"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax650s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93F89B44-3959-4709-B65D-F9B72646D746",
"versionEndExcluding": "7.10\\(abrm.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax650s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D784994E-E2CE-4328-B490-D9DC195A53DB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wax655e_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFF2B717-0B0C-4A10-86A6-ABFB592C4A52",
"versionEndExcluding": "7.10\\(acdo.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wax655e:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "61158220-B5E8-4BF4-B2C2-E8ABFD3266CF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wbe530_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAF5DBAB-37C2-4436-AA29-C48A0E88A673",
"versionEndExcluding": "7.10\\(acle.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wbe530:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3061579E-C708-42BC-86FC-B6223B941335"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:wbe660s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64D953D8-8351-44F4-ADCE-97F11DF62AE7",
"versionEndExcluding": "7.00\\(acgg.1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:wbe660s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9FC2F3A4-0598-49B0-9829-AF43C97E9E8E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:usg_lite_60ax_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C68921A-9FD4-41AA-A6A3-5F3BCC36C345",
"versionEndExcluding": "2.10\\(acip.0\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:usg_lite_60ax:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EC710993-3E55-4C88-A261-0A67F5069071"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]