OS Command Injection in ZyXEL Communications Corp. products - CVE-2024-7261
Published: September 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper neutralization of special elements in the "host" parameter in the CGI program. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
WAC6502D-S
WAC6503D-S
WAC6103D-I
WAC6552D-S
WAC500H
WAC6553D-E
WAC500
NWA1123ACv3
WAX510D
WAX610D
NWA110AX
WAX650S
WAX300H
NWA1123-AC PRO
NWA220AX-6E
WAX620D-6E
WAX630S
NWA130BE
WAX640S-6E
NWA90AX PRO
WAX655E
NWA90AX
WBE530
NWA55AXE
WBE660S
NWA50AX PRO
NWA50AX
USG LITE 60AX
How to mitigate CVE-2024-7261
WAC6502D-S - update to 6.28(AASE.3)
WAC6503D-S - update to 6.28(AASF.3)
WAC6103D-I - update to 6.28(AAXH.3)
WAC6552D-S - update to 6.28(ABIO.3)
WAC500H - update to 6.70(ABWA.5)
WAC6553D-E - update to 6.28(AASG.3)
WAC500 - update to 6.70(ABVS.5)
WAX300H - update to 7.00(ACHF.2)
NWA1123ACv3 - update to 6.70(ABVT.5)
WAX510D - update to 7.00(ABTF.2)
NWA1123-AC PRO - update to 6.28(ABHD.3)
WAX610D - update to 7.00(ABTE.2)
NWA220AX-6E - update to 7.00(ACCO.2)
WAX620D-6E - update to 7.00(ACCN.2)
WAX630S - update to 7.00(ABZD.2)
NWA130BE - update to 7.00(ACIL.2)
WAX640S-6E - update to 7.00(ACCM.2)
NWA110AX - update to 7.00(ABTG.2)
WAX650S - update to 7.00(ABRM.2)
NWA90AX PRO - update to 7.00(ACGF.2)
WAX655E - update to 7.00(ACDO.2)
NWA90AX - update to 7.00(ACCV.2)
WBE530 - update to 7.00(ACLE.2)
NWA55AXE - update to 7.00(ABZL.2)
WBE660S - update to 7.00(ACGG.2)
NWA50AX PRO - update to 7.00(ACGE.2)
NWA50AX - update to 7.00(ABYW.2)
USG LITE 60AX - update to 2.00(ACIP.3)