**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
History
No history.
Information
Published : 2024-09-10 02:15
Updated : 2025-01-22 22:31
NVD link : CVE-2024-6342
Mitre link : CVE-2024-6342
CVE.ORG link : CVE-2024-6342
JSON object : View
Products Affected
zyxel
- nas326
- nas542
- nas542_firmware
- nas326_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
