Home
HIGH: 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
V1.00(ABDV.3)C0
affected
Description
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Product status
V1.00(ABDV.3)C0
References
www.zyxel.com/global/en/support/end-of-life