First published: Tue Apr 09 2019(Updated: )
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel NAS326 firmware | <=5.21 | |
Zyxel NAS326 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10634 is an XSS vulnerability in the Zyxel NAS 326 version 5.21 and below.
CVE-2019-10634 allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
CVE-2019-10634 has a severity rating of 5.4 (Medium).
To fix CVE-2019-10634, you should update the Zyxel NAS 326 firmware to a version above 5.21.
You can find more information about CVE-2019-10634 at http://maxwelldulin.com/BlogPost?post=3236967424.