CVE-2024-9677: Zyxel Uos
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Affected products
- Zyxel Uos: before 1.30 (fixed in 1.30)
Published 2024-10-22. Last modified 2026-06-17.