Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2019-10633

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
0
Attacker Value
Unknown

CVE-2019-10632

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
0
Attacker Value
Unknown

CVE-2019-10630

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
0
Attacker Value
Unknown

CVE-2019-10634

Disclosure Date: April 09, 2019 (last updated November 27, 2024)
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
0