CVE-2022-34747: Critical severity zyxel nas326 vulnerability
Published Sep 6, 2022
·Updated
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
Affected Software
2 affected components
Zyxel NAS326<5.21\(aazf.12\)c0
Zyxel NAS326
Remediation
Event History
Sep 6, 2022
CVE Published
via MITRE·01:20 AM
Data Sourced
via MITRE·01:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-34747?
CVE-2022-34747 is a format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 that could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
2
How severe is CVE-2022-34747?
CVE-2022-34747 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2022-34747?
Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 are affected by CVE-2022-34747.
4
How can an attacker exploit CVE-2022-34747?
An attacker can exploit CVE-2022-34747 by sending a crafted UDP packet to the vulnerable Zyxel NAS326 firmware.
5
Is Zyxel NAS326 hardware affected by CVE-2022-34747?
No, Zyxel NAS326 hardware is not affected by CVE-2022-34747.