Shell Metacharacter Injection Vulnerability in Zyxel NAS Products
CVE-2019-10631
8.8HIGH
Summary
The Zyxel NAS 326 device is vulnerable to shell metacharacter injection, allowing an authenticated attacker to execute arbitrary code through specially crafted requests. This vulnerability arises from improper handling of input by the package installer, potentially leading to unauthorized code execution and compromising the device's integrity. Users of affected versions are urged to upgrade to mitigate risk.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved