PT-2019-11949 · Zyxel · Zyxel Nas326

Maxwell Dulin

·

Published

2019-04-09

·

Updated

2020-08-24

·

CVE-2019-10630

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel NAS 326 versions through 5.21
Description A plaintext password issue allows an elevated privileged user to obtain the admin password of the device.
Recommendations For versions through 5.21, update to a version that contains a fix for this issue to prevent elevated privileged users from accessing the admin password.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10630

Affected Products

Zyxel Nas326