vendor:
NWA-1100-NH
by:
Ahmed Alroky
8.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: NWA-1100-NH
Affected Version From: ALL BEFORE 2.12
Affected Version To: 2.12
Patch Exists: YES
Related CWE: CVE-2021-4039
CPE: h:zyxel:nwa-1100-nh
Platforms Tested: Linux
2022
Zyxel NWA-1100-NH – Command Injection
A command injection vulnerability exists in Zyxel NWA-1100-NH access points with firmware versions prior to 2.12. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the login page of the device. This request contains malicious code in the 'myname' parameter which is then executed on the device.
Mitigation:
Users should update their devices to the latest version of the firmware.