A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated malicious user to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zyxel nas326_firmware |
||
zyxel nas542_firmware |