Description

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

INFO

Published Date :

2024-09-03T02:10:25.112Z

Last Modified :

2024-09-05T15:36:14.807Z

Source :

Zyxel
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7261 vulnerability.

Vendors Products
Zyxel
  • Nwa110ax
  • Nwa110ax Firmware
  • Nwa1123-ac Pro
  • Nwa1123-ac Pro Firmware
  • Nwa1123acv3
  • Nwa1123acv3 Firmware
  • Nwa130be
  • Nwa130be Firmware
  • Nwa210ax
  • Nwa210ax Firmware
  • Nwa220ax-6e
  • Nwa220ax-6e Firmware
  • Nwa50ax
  • Nwa50ax Firmware
  • Nwa50ax Pro
  • Nwa50ax Pro Firmware
  • Nwa55axe
  • Nwa55axe Firmware
  • Nwa90ax
  • Nwa90ax Firmware
  • Nwa90ax Pro
  • Nwa90ax Pro Firmware
  • Usg Lite 60ax
  • Usg Lite 60ax Firmware
  • Wac500
  • Wac500 Firmware
  • Wac500h
  • Wac500h Firmware
  • Wac6103d-i
  • Wac6103d-i Firmware
  • Wac6502d-s
  • Wac6502d-s Firmware
  • Wac6503d-s
  • Wac6503d-s Firmware
  • Wac6552d-s
  • Wac6552d-s Firmware
  • Wac6553d-e
  • Wac6553d-e Firmware
  • Wax300h
  • Wax300h Firmware
  • Wax510d
  • Wax510d Firmware
  • Wax610d
  • Wax610d Firmware
  • Wax620d-6e
  • Wax620d-6e Firmware
  • Wax630s
  • Wax630s Firmware
  • Wax640s-6e
  • Wax640s-6e Firmware
  • Wax650s
  • Wax650s Firmware
  • Wax655e
  • Wax655e Firmware
  • Wbe530
  • Wbe530 Firmware
  • Wbe660s
  • Wbe660s Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7261.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact