A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.
2022-02-24T15:15:25.207
2024-11-21T06:36:45.350
Modified
CVSSv3.1: 8.0 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | zyxel | nbg6816_firmware | 1.00\(aawb.10\)c0 | Yes |
Hardware | zyxel | nbg6816 | - | No |
Operating System | zyxel | nbg6817_firmware | < 1.00\(abcs.11\)c0 | Yes |
Hardware | zyxel | nbg6817 | - | No |