A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZyxel Nwa1100 Nh
HWZyxelall versionsZyxel Nwa1100 Nh Firmware
OSZyxel< 2.12\(aasi.3\)c0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
Related vulnerabilities
CVE-2015-7256MEDIUM5.9same product
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG...
CVE-2023-27992CRITICAL9.8⚠ KEVPL ✓same vendor
Zyxel NAS — pre-authentication command injection w firmware NAS326/540/542
CVE-2023-33009CRITICAL9.8⚠ KEVPL ✓same vendor
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia
CVE-2023-33010CRITICAL9.8⚠ KEVPL ✓same vendor
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia (firewalle/VPN)
CVE-2023-28771CRITICAL9.8⚠ KEVPL ✓same vendor
Zyxel Firewall/VPN — zdalny command injection bez uwierzytelnienia (RCE)