📦 Nas326 Firmware

by Zyxel

🔍 What is Nas326 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-6342

CRITICAL CVSS 9.8 Sep 10, 2024

This is an unauthenticated command injection vulnerability in Zyxel NAS devices that allows remote attackers to execute arbitrary operating system commands. Attackers can exploit it by sending a craft...

CVE-2024-29974

CRITICAL CVSS 9.8 Jun 4, 2024

This critical vulnerability allows unauthenticated attackers to execute arbitrary code on affected Zyxel NAS devices by uploading a crafted configuration file to the vulnerable CGI program. It affects...

CVE-2024-29972

CRITICAL CVSS 9.8 Jun 4, 2024

This is a critical command injection vulnerability in Zyxel NAS devices that allows unauthenticated attackers to execute arbitrary operating system commands via crafted HTTP POST requests to the 'remo...

CVE-2023-4473

CRITICAL CVSS 9.8 Nov 30, 2023

An unauthenticated command injection vulnerability in Zyxel NAS web servers allows attackers to execute arbitrary OS commands by sending specially crafted URLs. This affects Zyxel NAS326 and NAS542 de...

CVE-2023-35138

CRITICAL CVSS 9.8 Nov 30, 2023

This critical command injection vulnerability in Zyxel NAS devices allows unauthenticated attackers to execute arbitrary operating system commands via crafted HTTP POST requests. Affected users includ...

CVE-2023-27992

CRITICAL CVSS 9.8 Jun 19, 2023

This is a critical pre-authentication command injection vulnerability in Zyxel NAS devices that allows unauthenticated remote attackers to execute arbitrary operating system commands via crafted HTTP ...

CVE-2023-37928

HIGH CVSS 8.8 Nov 30, 2023

A post-authentication command injection vulnerability in Zyxel NAS devices allows authenticated attackers to execute arbitrary OS commands by sending crafted URLs to the WSGI server. This affects Zyxe...

CVE-2023-27988

HIGH CVSS 7.2 May 30, 2023

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on affected Zyxel NAS326 devices. Attackers can remotely compromise the d...

CVE-2024-29976

MEDIUM CVSS 6.5 Jun 4, 2024

This vulnerability allows authenticated attackers on Zyxel NAS devices to view administrator session information including cookies via the 'show_allsessions' command. This affects Zyxel NAS326 and NAS...