2 results (0.002 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands. Una vulnerabilidad de inyección de comandos en el programa CGI de Zyxel VPN2S versión del firmware 1.12, podría permitir a un usuario local autenticado ejecutar comandos arbitrarios del sistema operativo • https://www.zyxel.com/support/Zyxel_security_advisory_for_directory_traversal_and_command_injection_vulnerabilities_of_VPN2S_Firewall.shtml • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information. Una vulnerabilidad de salto de directorio en el servidor web de Zyxel VPN2S versión del firmware 1.12, podría permitir a un atacante remoto acceder a información confidencial • https://www.zyxel.com/support/Zyxel_security_advisory_for_directory_traversal_and_command_injection_vulnerabilities_of_VPN2S_Firewall.shtml • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-27: Path Traversal: 'dir/../../filename' •