Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.zyxel.com/support/security_advisories.shtml | vendor advisory |
https://blog.somegeneric.ninja/Zyxel_VMG5153_B30B | third party advisory exploit |