Show filters
194 Total Results
Displaying 11-20 of 194
Sort by:
Attacker Value
Unknown

CVE-2024-29974

Disclosure Date: June 04, 2024 (last updated January 23, 2025)
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.
0
Attacker Value
Unknown

CVE-2024-29973

Disclosure Date: June 04, 2024 (last updated January 23, 2025)
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
0
Attacker Value
Unknown

CVE-2024-29972

Disclosure Date: June 04, 2024 (last updated January 23, 2025)
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
0
Attacker Value
Unknown

CVE-2024-33764

Disclosure Date: May 01, 2024 (last updated June 11, 2024)
lunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.
Attacker Value
Unknown

CVE-2023-5372

Disclosure Date: January 30, 2024 (last updated February 06, 2024)
The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands by sending a crafted query parameter attached to the URL of an affected device’s web management interface.
Attacker Value
Unknown

CVE-2023-51948

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web application.
Attacker Value
Unknown

CVE-2023-51947

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.
Attacker Value
Unknown

CVE-2023-51946

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.
Attacker Value
Unknown

CVE-2023-4474

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.
Attacker Value
Unknown

CVE-2023-4473

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.