CVE-2019-10631: Zyxel NAS326 Firmware

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.

Affected products

  • Zyxel NAS326 Firmware: up to and including 5.21

Published 2019-04-09. Last modified 2026-06-17.