Vulnerability record · CVE-2023-37928 · published 30 November 2023
CVE-2023-37928: Zyxel NAS WSGI server post-auth OS command injection
Zyxel · Nas326 Firmware
The WSGI server in Zyxel NAS326 and NAS542 firmware fails to sanitize input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary operating system commands on the device. Because the affected units are network-attached storage holding backups and shared files, this is a serious post-compromise escalation and data-theft risk.
Description
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high confidentiality, integrity and availability impact plus a 99th-percentile EPSS score, though exploitation requires valid credentials and no KEV listing exists.
What it is
The WSGI server in Zyxel NAS326 and NAS542 firmware fails to sanitize input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary operating system commands on the device. Because the affected units are network-attached storage holding backups and shared files, this is a serious post-compromise escalation and data-theft risk.
Impact
An authenticated attacker gains arbitrary OS command execution on the NAS, enabling data theft, file tampering, persistence, and use of the device as a foothold into the internal network.
Attack surface
Reachable over the network via a crafted URL sent to the WSGI server; the CVSS vector (AV:N/PR:L/UI:N) indicates network access with low privileges required and no user interaction.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.602 (99th percentile), indicating high predicted likelihood of exploitation; the vendor advisory is tagged Patch and Vendor Advisory.
What to do
- Apply the Zyxel security advisory firmware update for NAS326 and NAS542 as the first action.
- Restrict management and WSGI service access to trusted internal networks; do not expose the NAS to the internet.
- Enforce strong unique credentials and least-privilege accounts to limit who can reach the post-auth attack path.
- Monitor NAS accounts for unexpected creation or privilege changes and review device logs for anomalous command activity.
- If patching is delayed, isolate affected NAS devices on a segmented VLAN with no broad internal reachability.
Detection
- Alert on crafted or unusual URL patterns and parameters hitting the WSGI server, especially shell metacharacters.
- Monitor for unexpected child processes spawned by the WSGI/web service on the NAS.
- Watch for outbound connections from NAS devices to unfamiliar hosts, which may indicate command-and-control or exfiltration.
- Audit NAS authentication logs for logins from unusual source addresses preceding suspicious activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-37928 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-37928), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.