← Vulnerability feed

Vulnerability record · CVE-2023-5797 · published 28 November 2023

CVE-2023-5797: Zyxel zld improper privilege management vulnerability

Zyxel · Zld

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access the administrator’s logs on an affected device.

5.5 CVSS 3.1 Medium EPSS 0.21% · top 89.6% CWE-269 · Improper privilege management
5.5CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
20Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access the administrator’s logs on an affected device.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5797 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-7261Zyxel nwa110ax firmware os command injection vulnerabilityThe improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and ear…EPSS 11%8.8CVE-2024-12398Zyxel nwa50ax firmware improper privilege management vulnerabilityAn improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S…EPSS 0.54%7.8CVE-2022-26531Zyxel vpn100 firmware improper input validation vulnerabilityMultiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLE…EPSS 6.2%7.8CVE-2022-26532Zyxel vpn100 firmware argument injection vulnerabilityA argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series …EPSS 4.8%7.2CVE-2025-6265Zyxel nwa50ax firmware path traversal vulnerabilityA path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authe…EPSS 0.53%7.2CVE-2023-6398Zyxel atp100 firmware os command injection vulnerabilityA post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1,…EPSS 1.3%6.5CVE-2024-1575Zyxel nwa50ax firmware improper privilege management vulnerabilityThe improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated …EPSS 0.32%6.5CVE-2023-22918Zyxel atp200 firmware vulnerabilityA post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series …EPSS 0.77%

Source: NIST National Vulnerability Database (record CVE-2023-5797), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.