Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Zyxel DX3300-T0 操作系统命令注入漏洞
Vulnerability Description
Zyxel DX3300-T0是中国合勤(Zyxel)公司的一个小型无线WiFi路由器。 Zyxel DX3300-T0 5.50(ABVY.6.3)C0及之前版本存在操作系统命令注入漏洞,该漏洞源于priv参数存在认证后命令注入,可能导致操作系统命令执行。
CVSS Information
N/A
Vulnerability Type
N/A