CVE-2023-4473

CRITICAL EXPLOITED

Zyxel NAS326/NAS542 < 5.21(AAZF.14)C0/5.21(ABAG.11)C0 - Unauthenticated OS Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-4473 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Scores

CVSS v3 9.8
EPSS 0.3292
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-04-28
CWE
CWE-78
Status published
Products (2)
zyxel/nas326_firmware < 5.21\(aazf.14\)c0
zyxel/nas542_firmware < 5.21\(abag.11\)c0
Published Nov 30, 2023
Tracked Since Feb 18, 2026