PoC Index

CVE-2019-10631

HIGH 8.8EPSS 2.2%

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.25% chance of exploitation in the next 30 days, 82th percentile
Published
2019-04-09
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related