CVE-2019-10631: OS Command Injection
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability?
The vulnerability is a Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below that allows an authenticated attacker to execute arbitrary code via multiple different requests.
What is the severity of CVE-2019-10631?
The severity of CVE-2019-10631 is high, with a CVSS score of 8.8.
How can an attacker exploit the vulnerability?
An attacker can exploit the vulnerability by injecting shell metacharacters in the package installer on Zyxel NAS 326 version 5.21 and below.
Is the Zyxel NAS326 firmware affected?
Yes, Zyxel NAS326 firmware version 5.21 and below are affected by the vulnerability.
How can I fix the vulnerability in Zyxel NAS326?
To fix the vulnerability, it is recommended to update the Zyxel NAS326 firmware to a version above 5.21.