CVE-2023-27988

The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device remotely.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:zyxel:nas540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nas540:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-30 02:15

Updated : 2023-06-02 19:49


NVD link : CVE-2023-27988

Mitre link : CVE-2023-27988

CVE.ORG link : CVE-2023-27988


JSON object : View

Products Affected

zyxel

  • nas542
  • nas326_firmware
  • nas542_firmware
  • nas540_firmware
  • nas540
  • nas326
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')