← All CVEs

CVE-2024-7261

critical · 9.8

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

9.8
CVSS
11.4%
EPSS (exploit prob.)
96th
EPSS percentile
2024-09-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
zyxelnwa110ax_firmware< 7.00\(abtg.2\)
zyxelnwa110axall versions
zyxelnwa1123-ac_pro_firmware< 6.28\(abhd.3\)
zyxelnwa1123-ac_proall versions
zyxelnwa1123acv3_firmware< 6.70\(abvt.5\)
zyxelnwa1123acv3all versions
zyxelnwa130be_firmware< 7.00\(acil.2\)
zyxelnwa130beall versions
zyxelnwa210ax_firmware< 7.00\(abtd.2\)
zyxelnwa210axall versions
zyxelnwa220ax-6e_firmware< 7.00\(acco.2\)
zyxelnwa220ax-6eall versions
zyxelnwa50ax_firmware< 7.00\(abyw.2\)
zyxelnwa50axall versions
zyxelnwa50ax_pro_firmware< 7.00\(acge.2\)
zyxelnwa50ax_proall versions
zyxelnwa55axe_firmware< 7.00\(abzl.2\)
zyxelnwa55axeall versions
zyxelnwa90ax_firmware< 7.00\(accv.2\)
zyxelnwa90axall versions
zyxelnwa90ax_pro_firmware< 7.00\(acgf.2\)
zyxelnwa90ax_proall versions
zyxelusg_lite_60ax_firmware< v2.00\(acip.3\)
zyxelusg_lite_60axall versions
zyxelwac500_firmware< 6.70\(abvs.5\)
zyxelwac500all versions
zyxelwac500h_firmware< 6.70\(abwa.5\)
zyxelwac500hall versions
zyxelwac6103d-i_firmware< 6.28\(aaxh.3\)
zyxelwac6103d-iall versions
zyxelwac6502d-s_firmware< 6.28\(aase.3\)
zyxelwac6502d-sall versions
zyxelwac6503d-s_firmware< 6.28\(aasf.3\)
zyxelwac6503d-sall versions
zyxelwac6552d-s_firmware< 6.28\(abio.3\)
zyxelwac6552d-sall versions
zyxelwac6553d-e_firmware< 6.28\(aasg.3\)
zyxelwac6553d-eall versions
zyxelwax300h_firmware< 7.00\(achf.2\)
zyxelwax300hall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-7261