CVE-2023-27988
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device remotely.
Affected (3)
Products: Zyxel: Nas326 Firmware, Nas540 Firmware, Nas542 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.21\(aazf.13\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nas326 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.21\(aatb.10\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nas540 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.21\(abag.10\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Nas542 | All versions |
References (2)
Source: security@zyxel.com.tw
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.