CVE-2022-38546

MEDIUM

Zyxel NBG7510 <V1.00(ABZY.3)C0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
zyxel/nbg7510_firmware < 1.00\(abzy.2\)c0
Published Dec 21, 2022
Tracked Since Feb 18, 2026