Critical severity9.8NVD Advisory· Published Sep 6, 2022· Updated Jun 17, 2026
CVE-2022-34747
CVE-2022-34747
Description
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
Affected products
3cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*range: <5.21\(aazf.12\)c0
- (no CPE)range: < V5.21(AAZF.12)C0
Patches
Vulnerability mechanics
References
1- www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.