CVE-2019-10631

HIGH

Zyxel NAS326 Firmware < 5.21 - Authenticated OS Command Injection via Package Installer

Title source: llm
STIX 2.1

Description

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://maxwelldulin.com/BlogPost?post=3236967424

Scores

CVSS v3 8.8
EPSS 0.0070
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
zyxel/nas326_firmware < 5.21
Published Apr 09, 2019
Tracked Since Feb 18, 2026