CVE-2023-37927 HIGH

CVE-2023-37927

Vendor Zyxel
Product NAS326 firmware
Weakness CWE-78
Published November 30, 2023
Last update February 13, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Key dates

02Disclosure timeline

November 30, 2023 CVE published
February 13, 2025 Record updated