VDB

CVE-2024-7261

CVE-2024-7261 PUBLISHED CVSS 9.800000190734863 CRITICAL

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

EPSS 27.88% · 96.6th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
27.88%
96.6th percentile

Affected Products

VendorProductVersions
zyxelnwa130be_firmware0
zyxelwac6553d-e_firmware0
ZyxelUSG LITE 60AX firmwareV2.00(ACIP.2)
zyxelwac6503d-s_firmware0
zyxelwax655e_firmware0
zyxelnwa1123acv3_firmware0
zyxelnwa90ax_pro_firmware0
zyxelwax630s_firmware0
zyxelwax620d-6e_firmware0
zyxelwbe530_firmware0
zyxelusg_lite_60ax_firmware0
zyxelnwa55axe_firmware0
zyxelwac6103d-i_firmware0
zyxelwax510d_firmware0
zyxelwax640s-6e_firmware0
zyxelnwa210ax_firmware0
zyxelwax655e_firmware0
zyxelwac6502d-s_firmware0
zyxelwbe530_firmware0
zyxelwax650s_firmware0

…and 19 more

Timeline

  • Sep 3, 2024 EPSS Score
  • Sep 3, 2024 CVE Published
  • Sep 5, 2024 CVE Updated
  • Sep 23, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Nov 2, 2024 EPSS Score
  • Nov 22, 2024 EPSS Score
  • Dec 14, 2024 EPSS Score
  • Jan 3, 2025 EPSS Score
  • Feb 12, 2025 EPSS Score
  • Mar 4, 2025 EPSS Score
  • Mar 24, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›