← Back

CVE-2023-37927

nvd nist
Published: Nov 30, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Affected (2)

2 products
Nas326 Firmware
Nas542 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.21\(aazf.14\)c0
Running on/withPlatform Versions
Zyxel
Nas326
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.21\(abag.11\)c0
Running on/withPlatform Versions
Zyxel
Nas542
All versions

Timeline

No history available yet.