First published: Tue Apr 09 2019(Updated: )
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel NAS326 firmware | <=5.21 | |
Zyxel NAS326 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability is a Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below that allows an authenticated attacker to execute arbitrary code via multiple different requests.
The severity of CVE-2019-10631 is high, with a CVSS score of 8.8.
An attacker can exploit the vulnerability by injecting shell metacharacters in the package installer on Zyxel NAS 326 version 5.21 and below.
Yes, Zyxel NAS326 firmware version 5.21 and below are affected by the vulnerability.
To fix the vulnerability, it is recommended to update the Zyxel NAS326 firmware to a version above 5.21.