Zyxel security advisory for command injection vulnerability in the Wi-Fi SSID field of certain DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders

CVE: CVE-2023-20820

Summary

Zyxel has released patches for specific firmware versions of certain DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders devices using MediaTek Wi-Fi chipsets to address a post-authentication command injection vulnerability. Users are strongly advised to install these patches to ensure optimal protection.

It is important to note that the root cause of this vulnerability is the same as that of the publicly known vulnerability CVE-2023-20820. Zyxel did not receive any proactive notification from MediaTek before the researcher discovered that the vulnerability affected certain Zyxel devices.

 

What is the vulnerability?

A post-authentication command injection vulnerability in certain firmware versions for DSL/Ethernet CPE, fiber ONTs, and Wireless Extenders devices could allow an authenticated attacker with administrator privileges to execute OS commands via the Wi-Fi SSID field on an affected device. The vulnerability stems from the affected devices’ use of MediaTek chipsets and a vulnerable SDK provided by MediaTek. It was assigned CVE-2023-20820.

What versions are vulnerable—and what should you do?

After a thorough investigation, we identified the affected products still within their vulnerability support period and released firmware patches to address the issue, as shown in the table below. Please note that the table does not include customized models specifically designed for ISP customers. Any product currently on the market that is not listed in the table is not affected.

Affected modelAffected versionPatch availability
DSL/Ethernet CPE
DX3300-T05.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
DX3300-T15.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
DX3301-T05.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
EX3300-T05.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
EX3300-T15.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
EX3301-T05.50(ABVY.8.2)C0 and earlier5.50(ABVY.8.3)C0
EX3500-T05.44(ACHR.6)C0 and earlier5.44(ACHR.6.1)C0
EX3501-T05.44(ACHR.6)C0 and earlier5.44(ACHR.6.1)C0
EX3600-T05.70(ACIF.3.2)C0 and earlier5.70(ACIF.3.3)C0
EX5512-T05.70(ACEG.5.7)C0 and earlier5.70(ACEG.5.8)C0
EX5601-T05.70(ACDZ.6.2)C0 and earlier5.70(ACDZ.6.3)C0
EX5601-T15.70(ACDZ.6.2)C0 and earlier5.70(ACDZ.6.3)C0
Fiber ONTs
PX5301-T05.44(ACKB.0.8)C0 and earlier5.44(ACKB.0.9)C0
Wireless Extenders
WE3300-005.70(ACKA.2.1)C0 and earlier5.70(ACKA.2.2)C0
WX3100-T05.50(ABVL.5.1)C0 and earlier5.50(ABVL.5.2)C0
WX5600-T05.70(ACEB.6.2)C0 and earlier5.70(ACEB.6.3)C0
* Please contact your Zyxel sales representative or support team to obtain the file. Please note that the table does NOT include customized models specifically designed for ISP customers.

 

Got a question?

For our ISP customers, please contact your Zyxel sales or service representatives for more information. For customers who have acquired Zyxel devices through an ISP, please directly contact your ISP's support team, as the devices may have custom configurations.

 

Acknowledgment

Thanks to Ian Grody for reporting the issue to us.

 

Revision history

2026-10-06: Initial release