CVE-2023-27992

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 09, 2023
Published Date
June 19, 2023
Last Updated
January 27, 2025
Vendor
Zyxel
Product
NAS326 firmware, NAS540 firmware, NAS542 firmware
Description
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2023-06-23 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-06-23 00:00:00 UTC