Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
CVE-2023-33012 CVSS:8.8
Multiple Zyxel firewalls and WLAN controllers could allow a remote attacker to execute arbitrary commands on the system. By using a crafted GRE configuration, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-33011 CVSS:8.8
Multiple Zyxel firewalls and WLAN controllers could allow a remote attacker to execute arbitrary commands on the system. By using a crafted PPPoE configuration, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34138 CVSS:8
Zyxel firewalls and controllers could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by an OS command injection vulnerability in the hotspot management feature. By tricking an authorized administrator to add their IP address to the list of trusted RADIUS clients, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34139 CVSS:8.8
Zyxel firewalls could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by an OS command injection vulnerability in the Free Time WiFi hotspot feature. An attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34140 CVSS:6.5
Zyxel firewalls and controllers are vulnerable to a denial of service, caused by a buffer overflow. By sending a specially crafted request to the CAPWAP daemon, a remote attacker within the local network could exploit this vulnerability to cause a denial of service.
CVE-2023-34141 CVSS:8
Zyxel firewalls and controllers could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by a command injection vulnerability. By tricking an authorized administrator to add their IP address to the managed AP list, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Zyxel
Refer to the Zyxel Web site for patch, upgrade or suggested workaround information.