Zyxel Nas326 Firmware vulnerabilities
24 known vulnerabilities affecting zyxel/nas326_firmware.
Total CVEs
24
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH10MEDIUM4
Vulnerabilities
Page 2 of 2
CVE-2024-29976P3MEDIUMCVSS 6.5fixed in 5.21\(aazf.17\)c0fixed in V5.21(AAZF.17)C02024-06-04
CVE-2024-29976 [MEDIUM] CWE-269 CVE-2024-29976: ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show
** UNSUPPORTED WHEN ASSIGNED **
The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affec
nvd
CVE-2019-10632P3MEDIUMCVSS 6.5≤ 5.212019-04-09
CVE-2019-10632 [MEDIUM] CWE-22 CVE-2019-10632: A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
nvd
CVE-2024-29975P4MEDIUMCVSS 6.7fixed in 5.21\(aazf.17\)c0fixed in V5.21(AAZF.17)C02024-06-04
CVE-2024-29975 [MEDIUM] CWE-269 CVE-2024-29975: ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executab
** UNSUPPORTED WHEN ASSIGNED **
The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a
nvd
CVE-2019-10634P4MEDIUMCVSS 5.4≤ 5.212019-04-09
CVE-2019-10634 [MEDIUM] CWE-79 CVE-2019-10634: An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attac
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
nvd
← Previous2 / 2