CVE-2018-14893

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
27/11/2018
Last modified:
24/08/2020

Description

A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:nsa325_v2_firmware:4.81:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nsa325_v2:-:*:*:*:*:*:*:*