CVE-2022-34747
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.73%
- CWE
- CWE-134
- Published
- 2022-09-06
- Last modified
- 2026-03-13
Affected products
- Zyxel Zyxel NAS326 firmware
Weakness type
Related vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2012-10055 — ComSndFTP v1.3.7 Beta USER Format String RCE
- CVE-2023-35086 — ASUS RT-AX56U V2 & RT-AC86U - Format String -1
- CVE-2020-3118 — Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
- CVE-2011-10029 — Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
- CVE-2022-26674 — ASUS RT-AX88U - Format String
- CVE-2021-41193 — Use of Externally-Controlled Format String in wire-avs
- CVE-2023-35087 — ASUS RT-AX56U V2 & RT-AC86U - Format String - 2