Skip to main content

Vendor/product archive

zyxel / nas326 CVEs

Beta · best-effort

24 CVEs tagged to zyxel / nas32610 Critical, 10 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2022-34747

Published Sep 6, 2022

A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP p…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-10634

Published Apr 9, 2019

An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10633

Published Apr 9, 2019

An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10632

Published Apr 9, 2019

A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10631

Published Apr 9, 2019

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1