漏洞描述 ZyXEL Armor X1 WAP6806是中国台湾合勤(ZyXEL)公司的一款无线网卡产品。 ZyXEL Armor X1 WAP68061.00(ABAL.6)C0版本中存在路径遍历漏洞。该漏洞源于网络系统或产品未能正确地过滤资源或文件路径中的特殊元素。攻击者可利用该漏洞访问受限目录之外的位置。
相关漏洞推荐 POC CVE-2018-19326: Zyxel VMG1312-B10D 5.13AAXA.8 - Local File Inclusion POC CVE-2019-12581: Zyxel ZyWal/USG/UAG Devices - Cross-Site Scripting POC CVE-2019-12583: Zyxel ZyWall UAG/USG - Account Creation Access POC CVE-2019-9955: Zyxel - Cross-Site Scripting POC CVE-2020-29583: ZyXel USG - Hardcoded Credentials POC CVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code Execution POC CVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass POC CVE-2021-46387: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting POC CVE-2022-0342: Zyxel - Authentication Bypass POC CVE-2022-30525: Zyxel Firewall - OS Command Injection POC CVE-2024-29972: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor Account POC CVE-2024-29973: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection POC CVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication Bypass