← Back to browse · API

CVE-2024-7261

Severity
CRITICAL
CVSS
9.8
EPSS
0.11408
Risk score
43.19
CISA KEV
No
PoC
No
Published
2024-09-03
Modified
2024-09-05
First seen
2026-08-07
Aliases
EUVD-2024-48208, GHSA-4C9R-W43C-8V76
Products
Zyxel:NWA1123ACv3 firmware ≤ 6.70(ABVT.4), Zyxel:USG LITE 60AX firmware V2.00(ACIP.2), Zyxel:WAC500 firmware ≤ 6.70(ABVS.4), Zyxel:WAX655E firmware ≤ 7.00(ACDO.1), Zyxel:WBE530 firmware ≤ 7.00(ACLE.1)
Sources
euvd EUVD-2024-48208

Description

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

References