CVE-2024-7261
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
03/09/2024
Last modified:
13/09/2024
Description
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) <br />
<br />
and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) <br />
<br />
and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:nwa110ax_firmware:*:*:*:*:*:*:*:* | 7.00\(abtg.2\) (excluding) | |
| cpe:2.3:h:zyxel:nwa110ax:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa1123-ac_pro_firmware:*:*:*:*:*:*:*:* | 6.28\(abhd.3\) (excluding) | |
| cpe:2.3:h:zyxel:nwa1123-ac_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa1123acv3_firmware:*:*:*:*:*:*:*:* | 6.70\(abvt.5\) (excluding) | |
| cpe:2.3:h:zyxel:nwa1123acv3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa130be_firmware:*:*:*:*:*:*:*:* | 7.00\(acil.2\) (excluding) | |
| cpe:2.3:h:zyxel:nwa130be:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa210ax_firmware:*:*:*:*:*:*:*:* | 7.00\(abtd.2\) (excluding) | |
| cpe:2.3:h:zyxel:nwa210ax:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa220ax-6e_firmware:*:*:*:*:*:*:*:* | 7.00\(acco.2\) (excluding) | |
| cpe:2.3:h:zyxel:nwa220ax-6e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa50ax_firmware:*:*:*:*:*:*:*:* | 7.00\(abyw.2\) (excluding) | |
| cpe:2.3:h:zyxel:nwa50ax:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:zyxel:nwa50ax_pro_firmware:*:*:*:*:*:*:*:* | 7.00\(acge.2\) (excluding) |
To consult the complete list of CPE names with products and versions, see this page



