Overview
- Description
- The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
- Source
- security@zyxel.com.tw
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Known exploits
Data from CISA
- Vulnerability name
- Zyxel Multiple NAS Devices Command Injection Vulnerability
- Exploit added on
- Jun 23, 2023
- Exploit action due
- Jul 14, 2023
- Required action
- Apply updates per vendor instructions.
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E0A01B19-4A91-4FBC-8447-2E854346DAC5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1C7EF7A-7A3B-4DAB-B42A-2C84F861A5D2", "versionEndIncluding": "5.21\\(aazf.13\\)c0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:zyxel:nas540:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B2F7264C-D32A-4EE9-BADC-78518D762BCA" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:zyxel:nas540_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E8018F0-97F9-46E1-954B-08BA1BCE33AB", "versionEndIncluding": "5.21\\(aatb.10\\)c0" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "31C4DD0F-28D0-4BF7-897B-5EEC32AA7277" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F106841-EEF2-4EFA-BD32-514AF9C74F22", "versionEndIncluding": "5.21\\(abag.10\\)c0" } ], "operator": "OR" } ], "operator": "AND" } ]