A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device.
| Vendor | Product | Versions |
|---|---|---|
| zyxel | dx3300-t0 firmware | <= 5.50(ABVY.7.1)C0 |
Updated severity to CRITICAL and marked the vulnerability as actively exploited.
Initial creation