CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an un...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Jun 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.1...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Jun 4, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Jun 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Jun 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareJan 22, 2025 Jun 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 coul...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Jan 30, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administ...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute som...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating sys...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker t...Show more |
1Zyxel 2Nas326 Firmware Nas542 FirmwareNov 21, 2024 Nov 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain s...Show more |
1Zyxel 3Nas326 Firmware Nas540 FirmwareNas542 FirmwareOct 27, 2025 Jun 19, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG...Show more |
1Zyxel 3Nas326 Firmware Nas540 FirmwareNas542 FirmwareNov 21, 2024 May 30, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system...Show more |
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet. |
1Zyxel 4Nas326 Firmware Nas520 FirmwareNas540 Firmware+1 moreNov 21, 2024 Aug 6, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)...Show more |
1Zyxel 4Nas326 Firmware Nas520 FirmwareNas540 Firmware+1 moreNov 21, 2024 Aug 6, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and...Show more |
1Zyxel 27Atp100 Firmware Atp200 FirmwareAtp500 Firmware+24 moreNov 10, 2025 Mar 4, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary co...Show more |
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields. |