Описание
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.
Ссылки
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:zyxel:nwaw1100-n_firmware:1.00\(aace.1\)c0:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nwaw1100-n:-:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.0762
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 7.5
github
больше 1 года назад
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.
EPSS
Процентиль: 92%
0.0762
Низкий
7.5 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-78