CVE-2019-10633: Code Injection
Published Apr 9, 2019
·Updated
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
Affected Software
2 affected components
Zyxel NAS326<=5.21
Zyxel NAS326
Event History
Apr 9, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-10633?
CVE-2019-10633 is an eval injection vulnerability in the Zyxel NAS 326 version 5.21 and below.
2
How does CVE-2019-10633 affect Zyxel NAS 326?
CVE-2019-10633 allows a remote authenticated attacker to execute arbitrary code via specific APIs on the Zyxel NAS 326.
3
How severe is CVE-2019-10633?
CVE-2019-10633 has a severity score of 8.8, which is considered high.
4
How can I fix CVE-2019-10633?
To fix CVE-2019-10633, update the Zyxel NAS 326 firmware to version 5.22 or higher.
5
Where can I find more information about CVE-2019-10633?
You can find more information about CVE-2019-10633 at http://maxwelldulin.com/BlogPost?post=3236967424.