CVE-2023-37928 HIGH

CVE-2023-37928

Vendor Zyxel
Product NAS326 firmware
Weakness CWE-78
Published November 30, 2023
Last update February 13, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Key dates

02Disclosure timeline

November 30, 2023 CVE published
February 13, 2025 Record updated