A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
2021-09-29T11:15:07.547
2024-11-21T06:11:42.157
Modified
CVSSv3.1: 7.3 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zyxel | zywall_vpn2s_firmware | 1.12\(abln.0\)c0 | Yes |
Hardware | zyxel | zywall_vpn2s | - | No |