CVE-2024-7261
published 2024-09-03CVE-2024-7261: The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier…
PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.27%
95.5th percentile
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4)
and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1)
and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | nwa110ax_firmware | < 7.00\(abtg.2\) | 7.00\(abtg.2\) |
| zyxel | nwa1123-ac_pro_firmware | < 6.28\(abhd.3\) | 6.28\(abhd.3\) |
| zyxel | nwa1123acv3_firmware | < 6.70\(abvt.5\) | 6.70\(abvt.5\) |
| zyxel | nwa1123acv3_firmware | <= 6.70(ABVT.4) | — |
| zyxel | nwa130be_firmware | < 7.00\(acil.2\) | 7.00\(acil.2\) |
| zyxel | nwa210ax_firmware | < 7.00\(abtd.2\) | 7.00\(abtd.2\) |
| zyxel | nwa220ax-6e_firmware | < 7.00\(acco.2\) | 7.00\(acco.2\) |
| zyxel | nwa50ax_firmware | < 7.00\(abyw.2\) | 7.00\(abyw.2\) |
| zyxel | nwa50ax_pro_firmware | < 7.00\(acge.2\) | 7.00\(acge.2\) |
| zyxel | nwa55axe_firmware | < 7.00\(abzl.2\) | 7.00\(abzl.2\) |
| zyxel | nwa90ax_firmware | < 7.00\(accv.2\) | 7.00\(accv.2\) |
| zyxel | nwa90ax_pro_firmware | < 7.00\(acgf.2\) | 7.00\(acgf.2\) |
| zyxel | usg_lite_60ax_firmware | < v2.00\(acip.3\) | v2.00\(acip.3\) |
| zyxel | usg_lite_60ax_firmware | — | — |
| zyxel | wac500_firmware | < 6.70\(abvs.5\) | 6.70\(abvs.5\) |
| zyxel | wac500_firmware | <= 6.70(ABVS.4) | — |
| zyxel | wac500h_firmware | < 6.70\(abwa.5\) | 6.70\(abwa.5\) |
| zyxel | wac6103d-i_firmware | < 6.28\(aaxh.3\) | 6.28\(aaxh.3\) |
| zyxel | wac6502d-s_firmware | < 6.28\(aase.3\) | 6.28\(aase.3\) |
| zyxel | wac6503d-s_firmware | < 6.28\(aasf.3\) | 6.28\(aasf.3\) |
| zyxel | wac6552d-s_firmware | < 6.28\(abio.3\) | 6.28\(abio.3\) |
| zyxel | wac6553d-e_firmware | < 6.28\(aasg.3\) | 6.28\(aasg.3\) |
| zyxel | wax300h_firmware | < 7.00\(achf.2\) | 7.00\(achf.2\) |
| zyxel | wax510d_firmware | < 7.00\(abtf.2\) | 7.00\(abtf.2\) |
| zyxel | wax610d_firmware | < 7.00\(abte.2\) | 7.00\(abte.2\) |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor CGI program requests where the 'host' parameter contains special elements or shell metacharacters, particularly from unauthenticated sources ↗
- →Inspect HTTP Cookie headers in requests to Zyxel access point and security router CGI endpoints for OS command injection payloads ↗
- ·Vulnerability affects multiple Zyxel device families across different firmware version lines; ensure version scope is confirmed before applying detection rules ↗
- ·The attack vector is unauthenticated, meaning no prior session or credentials are required — perimeter controls blocking unauthenticated CGI access are a relevant mitigation layer ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
9th September – Threat Intelligence Report
blogs_checkpoint·2024-09-09
CVE-2024-32896 9th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The German air traffic control agency, Deutsche Flugsicherung, has confirmed a cyberattack that impacted its administrative IT infrastructure. The extent of data accessed is still under investigation, and flight operations remained unaffected. No threat actor has claimed responsibility yet, though the attack is suspecte
Bleepingcomputer
Zyxel warns of critical OS command injection flaw in routers
blogs_bleepingcomputer·2024-09-03·CVSS 8.1
CVE-2024-7261 [HIGH] Zyxel warns of critical OS command injection flaw in routers
## Zyxel warns of critical OS command injection flaw in routers
## Bill Toulas
The Zyxel access points (APs) impacted by CVE-2024-7261 are the following:
NWA Series : NWA50AX, NWA50AX PRO, NWA55AXE, NWA90AX, NWA90AX PRO, NWA110AX, NWA130BE, NWA210AX, NWA220AX-6E | all versions up to 7.00 are vulnerable, upgrade to 7.00(ABYW.2) and later
NWA1123-AC PRO | all versions up to 6.28 are vulnerable, upgrade to 6.28(ABHD.3) and later
NWA1123ACv3, WAC500, WAC500H | all versions up to 6.70 are vulnerable, upgrade to 6.70(ABVT.5) and later
WAC Series : WAC6103D-I, WAC6502D-S, WAC6503D-S, WAC6552D-S, WAC6553D-E | all versions up to 6.28 are vulnerable, upgrade to 6.28(AAXH.3) and later
WAX Series : WAX300H, WAX510D, WAX610D, WAX620D-6E, WAX630S, WAX640S-6E, WAX650S, WAX655E | all versions up to
Greynoiseio
NoiseLetter October 2024
blogs_greynoiseio
NoiseLetter October 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2024-09-03
Published