CVE-2024-7261
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.
Published:Sep 3, 2024
Last Modified:Sep 13, 2024
EPS:Sep 3, 2024
EPSS Score:0.02808
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Nwa110ax
Zyxel
Nwa110ax
Vendor
Zyxel
Product
Nwa110ax Firmware
Zyxel
Nwa110ax Firmware
Vendor
Zyxel
Product
Nwa1123-ac Pro
Zyxel
Nwa1123-ac Pro
Vendor
Zyxel
Product
Nwa1123-ac Pro Firmware
Zyxel
Nwa1123-ac Pro Firmware
Vendor
Zyxel
Product
Nwa1123acv3
Zyxel
Nwa1123acv3
Vendor
Zyxel
Product
Nwa1123acv3 Firmware
Zyxel
Nwa1123acv3 Firmware
Vendor
Zyxel
Product
Nwa130be
Zyxel
Nwa130be
Vendor
Zyxel
Product
Nwa130be Firmware
Zyxel
Nwa130be Firmware
Vendor
Zyxel
Product
Nwa210ax
Zyxel
Nwa210ax
Vendor
Zyxel
Product
Nwa210ax Firmware
Zyxel
Nwa210ax Firmware
Vendor
Zyxel
Product
Nwa220ax-6e
Zyxel
Nwa220ax-6e
Vendor
Zyxel
Product
Nwa220ax-6e Firmware
Zyxel
Nwa220ax-6e Firmware
Vendor
Zyxel
Product
Nwa50ax
Zyxel
Nwa50ax
Vendor
Zyxel
Product
Nwa50ax Firmware
Zyxel
Nwa50ax Firmware
Vendor
Zyxel
Product
Nwa50ax Pro
Zyxel
Nwa50ax Pro
Vendor
Zyxel
Product
Nwa50ax Pro Firmware
Zyxel
Nwa50ax Pro Firmware
Vendor
Zyxel
Product
Nwa55axe
Zyxel
Nwa55axe
Vendor
Zyxel
Product
Nwa55axe Firmware
Zyxel
Nwa55axe Firmware
Vendor
Zyxel
Product
Nwa90ax
Zyxel
Nwa90ax
Vendor
Zyxel
Product
Nwa90ax Firmware
Zyxel
Nwa90ax Firmware
Vendor
Zyxel
Product
Nwa90ax Pro
Zyxel
Nwa90ax Pro
Vendor
Zyxel
Product
Nwa90ax Pro Firmware
Zyxel
Nwa90ax Pro Firmware
Vendor
Zyxel
Product
Usg Lite 60ax
Zyxel
Usg Lite 60ax
Vendor
Zyxel
Product
Usg Lite 60ax Firmware
Zyxel
Usg Lite 60ax Firmware
Vendor
Zyxel
Product
Wac500
Zyxel
Wac500
Vendor
Zyxel
Product
Wac500 Firmware
Zyxel
Wac500 Firmware
Vendor
Zyxel
Product
Wac500h
Zyxel
Wac500h
Vendor
Zyxel
Product
Wac500h Firmware
Zyxel
Wac500h Firmware
Vendor
Zyxel
Product
Wac6103d-i
Zyxel
Wac6103d-i
Vendor
Zyxel
Product
Wac6103d-i Firmware
Zyxel
Wac6103d-i Firmware
Vendor
Zyxel
Product
Wac6502d-s
Zyxel
Wac6502d-s
Vendor
Zyxel
Product
Wac6502d-s Firmware
Zyxel
Wac6502d-s Firmware
Vendor
Zyxel
Product
Wac6503d-s
Zyxel
Wac6503d-s
Vendor
Zyxel
Product
Wac6503d-s Firmware
Zyxel
Wac6503d-s Firmware
Vendor
Zyxel
Product
Wac6552d-s
Zyxel
Wac6552d-s
Vendor
Zyxel
Product
Wac6552d-s Firmware
Zyxel
Wac6552d-s Firmware
Vendor
Zyxel
Product
Wac6553d-e
Zyxel
Wac6553d-e
Vendor
Zyxel
Product
Wac6553d-e Firmware
Zyxel
Wac6553d-e Firmware
Vendor
Zyxel
Product
Wax300h
Zyxel
Wax300h
Vendor
Zyxel
Product
Wax300h Firmware
Zyxel
Wax300h Firmware
Vendor
Zyxel
Product
Wax510d
Zyxel
Wax510d
Vendor
Zyxel
Product
Wax510d Firmware
Zyxel
Wax510d Firmware
Vendor
Zyxel
Product
Wax610d
Zyxel
Wax610d
Vendor
Zyxel
Product
Wax610d Firmware
Zyxel
Wax610d Firmware
Vendor
Zyxel
Product
Wax620d-6e
Zyxel
Wax620d-6e
Vendor
Zyxel
Product
Wax620d-6e Firmware
Zyxel
Wax620d-6e Firmware
Vendor
Zyxel
Product
Wax630s
Zyxel
Wax630s
Vendor
Zyxel
Product
Wax630s Firmware
Zyxel
Wax630s Firmware
Vendor
Zyxel
Product
Wax640s-6e
Zyxel
Wax640s-6e
Vendor
Zyxel
Product
Wax640s-6e Firmware
Zyxel
Wax640s-6e Firmware
Vendor
Zyxel
Product
Wax650s
Zyxel
Wax650s
Vendor
Zyxel
Product
Wax650s Firmware
Zyxel
Wax650s Firmware
Vendor
Zyxel
Product
Wax655e
Zyxel
Wax655e
Vendor
Zyxel
Product
Wax655e Firmware
Zyxel
Wax655e Firmware
Vendor
Zyxel
Product
Wbe530
Zyxel
Wbe530
Vendor
Zyxel
Product
Wbe530 Firmware
Zyxel
Wbe530 Firmware
Vendor
Zyxel
Product
Wbe660s
Zyxel
Wbe660s
Vendor
Zyxel
Product
Wbe660s Firmware
Zyxel
Wbe660s Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
