peter bassill · operator
$ cve CVE-2024-7261 JSON

CVE-2024-7261

9.8
CRITICAL · CVSS 3.1 · EPSS 11.4% (pctl 96)

Patch early

EPSS 11.4% — above the 10% action threshold.

Description

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS11.41% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2024-09-03
Last modified2026-06-17

Affected (40)

VendorProduct
zyxelnwa110ax
zyxelnwa110ax firmware
zyxelnwa1123-ac pro
zyxelnwa1123-ac pro firmware
zyxelnwa1123acv3
zyxelnwa1123acv3 firmware
zyxelnwa130be
zyxelnwa130be firmware
zyxelnwa210ax
zyxelnwa210ax firmware
zyxelnwa220ax-6e
zyxelnwa220ax-6e firmware
zyxelnwa50ax
zyxelnwa50ax firmware
zyxelnwa50ax pro
zyxelnwa50ax pro firmware
zyxelnwa55axe
zyxelnwa55axe firmware
zyxelnwa90ax
zyxelnwa90ax firmware
zyxelnwa90ax pro
zyxelnwa90ax pro firmware
zyxelusg lite 60ax
zyxelusg lite 60ax firmware
zyxelwac500
zyxelwac500 firmware
zyxelwac500h
zyxelwac500h firmware
zyxelwac6103d-i
zyxelwac6103d-i firmware
zyxelwac6502d-s
zyxelwac6502d-s firmware
zyxelwac6503d-s
zyxelwac6503d-s firmware
zyxelwac6552d-s
zyxelwac6552d-s firmware
zyxelwac6553d-e
zyxelwac6553d-e firmware
zyxelwax300h
zyxelwax300h firmware

References

→ the Explorer  ·  watch your stack  ·  NVD