← Back

CVE-2023-4474

nvd nist
Published: Nov 30, 2023Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Affected (2)

2 products
Nas326 Firmware
Nas542 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.21\(aazf.14\)c0
Running on/withPlatform Versions
Zyxel
Nas326
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.21\(abag.11\)c0
Running on/withPlatform Versions
Zyxel
Nas542
All versions

Timeline

No history available yet.