CVE-2022-34747

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
06/09/2022
Last modified:
08/09/2022

Description

A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:* 5.21\(aazf.12\)c0 (excluding)
cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*