CVE-2024-7261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
03/09/2024
Last modified:
13/09/2024

Description

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) <br /> <br /> and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) <br /> <br /> and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:nwa110ax_firmware:*:*:*:*:*:*:*:* 7.00\(abtg.2\) (excluding)
cpe:2.3:h:zyxel:nwa110ax:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa1123-ac_pro_firmware:*:*:*:*:*:*:*:* 6.28\(abhd.3\) (excluding)
cpe:2.3:h:zyxel:nwa1123-ac_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa1123acv3_firmware:*:*:*:*:*:*:*:* 6.70\(abvt.5\) (excluding)
cpe:2.3:h:zyxel:nwa1123acv3:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa130be_firmware:*:*:*:*:*:*:*:* 7.00\(acil.2\) (excluding)
cpe:2.3:h:zyxel:nwa130be:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa210ax_firmware:*:*:*:*:*:*:*:* 7.00\(abtd.2\) (excluding)
cpe:2.3:h:zyxel:nwa210ax:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa220ax-6e_firmware:*:*:*:*:*:*:*:* 7.00\(acco.2\) (excluding)
cpe:2.3:h:zyxel:nwa220ax-6e:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa50ax_firmware:*:*:*:*:*:*:*:* 7.00\(abyw.2\) (excluding)
cpe:2.3:h:zyxel:nwa50ax:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:nwa50ax_pro_firmware:*:*:*:*:*:*:*:* 7.00\(acge.2\) (excluding)