Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-934v-v4wh-rf2c

Опубликовано: 24 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

EPSS

Процентиль: 40%
0.00181
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

CVSS3: 9.8
fstec
4 месяца назад

Уязвимость реализации протокола UPnP микропрограммного обеспечения сетевых устройств Zyxel, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 40%
0.00181
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78