** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zyxel
Zyxel nwa1100-n Firmware |
|
CPEs | cpe:2.3:o:zyxel:nwa1100-n_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Zyxel
Zyxel nwa1100-n Firmware |
|
Metrics |
ssvc
|
Fri, 30 Aug 2024 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Zyxel
Published: 2024-08-30T00:28:43.562Z
Updated: 2024-08-30T14:53:25.378Z
Reserved: 2024-08-27T14:36:14.823Z
Link: CVE-2024-8234
Vulnrichment
Updated: 2024-08-30T14:45:37.332Z
NVD
Status : Awaiting Analysis
Published: 2024-08-30T01:15:03.797
Modified: 2024-08-30T13:00:05.390
Link: CVE-2024-8234
Redhat
No data.