cbcvebase.
CVE-2024-7261
published 2024-09-03

CVE-2024-7261: The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier…

PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
11.27%
95.5th percentile
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelnwa110ax_firmware< 7.00\(abtg.2\)7.00\(abtg.2\)
zyxelnwa1123-ac_pro_firmware< 6.28\(abhd.3\)6.28\(abhd.3\)
zyxelnwa1123acv3_firmware< 6.70\(abvt.5\)6.70\(abvt.5\)
zyxelnwa1123acv3_firmware<= 6.70(ABVT.4)
zyxelnwa130be_firmware< 7.00\(acil.2\)7.00\(acil.2\)
zyxelnwa210ax_firmware< 7.00\(abtd.2\)7.00\(abtd.2\)
zyxelnwa220ax-6e_firmware< 7.00\(acco.2\)7.00\(acco.2\)
zyxelnwa50ax_firmware< 7.00\(abyw.2\)7.00\(abyw.2\)
zyxelnwa50ax_pro_firmware< 7.00\(acge.2\)7.00\(acge.2\)
zyxelnwa55axe_firmware< 7.00\(abzl.2\)7.00\(abzl.2\)
zyxelnwa90ax_firmware< 7.00\(accv.2\)7.00\(accv.2\)
zyxelnwa90ax_pro_firmware< 7.00\(acgf.2\)7.00\(acgf.2\)
zyxelusg_lite_60ax_firmware< v2.00\(acip.3\)v2.00\(acip.3\)
zyxelusg_lite_60ax_firmware
zyxelwac500_firmware< 6.70\(abvs.5\)6.70\(abvs.5\)
zyxelwac500_firmware<= 6.70(ABVS.4)
zyxelwac500h_firmware< 6.70\(abwa.5\)6.70\(abwa.5\)
zyxelwac6103d-i_firmware< 6.28\(aaxh.3\)6.28\(aaxh.3\)
zyxelwac6502d-s_firmware< 6.28\(aase.3\)6.28\(aase.3\)
zyxelwac6503d-s_firmware< 6.28\(aasf.3\)6.28\(aasf.3\)
zyxelwac6552d-s_firmware< 6.28\(abio.3\)6.28\(abio.3\)
zyxelwac6553d-e_firmware< 6.28\(aasg.3\)6.28\(aasg.3\)
zyxelwax300h_firmware< 7.00\(achf.2\)7.00\(achf.2\)
zyxelwax510d_firmware< 7.00\(abtf.2\)7.00\(abtf.2\)
zyxelwax610d_firmware< 7.00\(abte.2\)7.00\(abte.2\)

Detection & IOCsextracted from sources · hover to see the quote

cookiecrafted cookie to exploit host parameter in CGI program
  • Monitor CGI program requests where the 'host' parameter contains special elements or shell metacharacters, particularly from unauthenticated sources
  • Inspect HTTP Cookie headers in requests to Zyxel access point and security router CGI endpoints for OS command injection payloads
  • ·Vulnerability affects multiple Zyxel device families across different firmware version lines; ensure version scope is confirmed before applying detection rules
  • ·The attack vector is unauthenticated, meaning no prior session or credentials are required — perimeter controls blocking unauthenticated CGI access are a relevant mitigation layer
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.