9.8

CVE-2024-7261

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) 

and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) 

and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelNwa110ax Firmware Version < 7.00\(abtg.2\)
   ZyxelNwa110ax Version-
ZyxelNwa1123-ac Pro Firmware Version < 6.28\(abhd.3\)
   ZyxelNwa1123-ac Pro Version-
ZyxelNwa1123acv3 Firmware Version < 6.70\(abvt.5\)
   ZyxelNwa1123acv3 Version-
ZyxelNwa130be Firmware Version < 7.00\(acil.2\)
   ZyxelNwa130be Version-
ZyxelNwa210ax Firmware Version < 7.00\(abtd.2\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version < 7.00\(acco.2\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa50ax Firmware Version < 7.00\(abyw.2\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax Pro Firmware Version < 7.00\(acge.2\)
   ZyxelNwa50ax Pro Version-
ZyxelNwa55axe Firmware Version < 7.00\(abzl.2\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version < 7.00\(accv.2\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax Pro Firmware Version < 7.00\(acgf.2\)
   ZyxelNwa90ax Pro Version-
ZyxelUsg Lite 60ax Firmware Version < v2.00\(acip.3\)
   ZyxelUsg Lite 60ax Version-
ZyxelWac500 Firmware Version < 6.70\(abvs.5\)
   ZyxelWac500 Version-
ZyxelWac500h Firmware Version < 6.70\(abwa.5\)
   ZyxelWac500h Version-
ZyxelWac6103d-i Firmware Version < 6.28\(aaxh.3\)
   ZyxelWac6103d-i Version-
ZyxelWac6502d-s Firmware Version < 6.28\(aase.3\)
   ZyxelWac6502d-s Version-
ZyxelWac6503d-s Firmware Version < 6.28\(aasf.3\)
   ZyxelWac6503d-s Version-
ZyxelWac6552d-s Firmware Version < 6.28\(abio.3\)
   ZyxelWac6552d-s Version-
ZyxelWac6553d-e Firmware Version < 6.28\(aasg.3\)
   ZyxelWac6553d-e Version-
ZyxelWax300h Firmware Version < 7.00\(achf.2\)
   ZyxelWax300h Version-
ZyxelWax510d Firmware Version < 7.00\(abtf.2\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version < 7.00\(abte.2\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version < 7.00\(accn.2\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version < 7.00\(abzd.2\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version < 7.00\(accm.2\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version < 7.00\(abrm.2\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version < 7.00\(acdo.2\)
   ZyxelWax655e Version-
ZyxelWbe530 Firmware Version < 7.00\(acle.2\)
   ZyxelWbe530 Version-
ZyxelWbe660s Firmware Version < 7.00\(acgg.2\)
   ZyxelWbe660s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.81% 0.856
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.