CVE-2022-38546 MEDIUM

CVE-2022-38546

Vendor Zyxel
Product NBG7510 firmware
Weakness CWE-284
Published December 21, 2022
Last update April 15, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.

Key dates

02Disclosure timeline

December 21, 2022 CVE published
April 15, 2025 Record updated