← Back to browse · API

CVE-2024-6342

Severity
CRITICAL
CVSS
9.8
EPSS
0.02064
Risk score
39.92
CISA KEV
No
PoC
No
Published
2024-09-10
Modified
2024-09-10
First seen
2026-08-07
Aliases
EUVD-2024-47455, GHSA-CJPP-26J6-262M
Products
Zyxel:NAS326 firmware ≤ V5.21(AAZF.18)C0, Zyxel:NAS542 firmware ≤ V5.21(ABAG.15)C0
Sources
euvd EUVD-2024-47455

Description

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

References