VDB
CVE-2024-7261
CVE-2024-7261
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.
EPSS 27.88% · 96.6th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
27.88%
96.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| zyxel | nwa130be_firmware | 0 |
| zyxel | wac6553d-e_firmware | 0 |
| Zyxel | USG LITE 60AX firmware | V2.00(ACIP.2) |
| zyxel | wac6503d-s_firmware | 0 |
| zyxel | wax655e_firmware | 0 |
| zyxel | nwa1123acv3_firmware | 0 |
| zyxel | nwa90ax_pro_firmware | 0 |
| zyxel | wax630s_firmware | 0 |
| zyxel | wax620d-6e_firmware | 0 |
| zyxel | wbe530_firmware | 0 |
| zyxel | usg_lite_60ax_firmware | 0 |
| zyxel | nwa55axe_firmware | 0 |
| zyxel | wac6103d-i_firmware | 0 |
| zyxel | wax510d_firmware | 0 |
| zyxel | wax640s-6e_firmware | 0 |
| zyxel | nwa210ax_firmware | 0 |
| zyxel | wax655e_firmware | 0 |
| zyxel | wac6502d-s_firmware | 0 |
| zyxel | wbe530_firmware | 0 |
| zyxel | wax650s_firmware | 0 |
…and 19 more
Timeline
- Sep 3, 2024 EPSS Score
- Sep 3, 2024 CVE Published
- Sep 5, 2024 CVE Updated
- Sep 23, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Nov 2, 2024 EPSS Score
- Nov 22, 2024 EPSS Score
- Dec 14, 2024 EPSS Score
- Jan 3, 2025 EPSS Score
- Feb 12, 2025 EPSS Score
- Mar 4, 2025 EPSS Score
- Mar 24, 2025 EPSS Score