First published: Tue Sep 10 2024(Updated: )
**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel NAS326 | <=V5.21(AAZF.18)C0 | |
Zyxel NAS542 firmware | <=V5.21(ABAG.15)C0 | |
All of | ||
Any of | ||
Zyxel NAS326 firmware | <5.21\(aazf.18\)c0 | |
Zyxel NAS326 firmware | =5.21\(aazf.18\)c0 | |
Zyxel NAS326 | ||
All of | ||
Any of | ||
Zyxel NAS542 firmware | <5.21\(abag.15\)c0 | |
Zyxel NAS542 firmware | =5.21\(abag.15\)c0 | |
Zyxel NAS542 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.