← Vulnerability feed

Vulnerability record · CVE-2023-37928 · published 30 November 2023

CVE-2023-37928: Zyxel NAS WSGI server post-auth OS command injection

Zyxel · Nas326 Firmware

The WSGI server in Zyxel NAS326 and NAS542 firmware fails to sanitize input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary operating system commands on the device. Because the affected units are network-attached storage holding backups and shared files, this is a serious post-compromise escalation and data-theft risk.

8.8 CVSS 3.1 High EPSS 60% · top 0.9% CWE-78 · OS command injection
8.8CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with high confidentiality, integrity and availability impact plus a 99th-percentile EPSS score, though exploitation requires valid credentials and no KEV listing exists.

What it is

The WSGI server in Zyxel NAS326 and NAS542 firmware fails to sanitize input, allowing OS command injection. An attacker who already holds valid credentials can run arbitrary operating system commands on the device. Because the affected units are network-attached storage holding backups and shared files, this is a serious post-compromise escalation and data-theft risk.

Impact

An authenticated attacker gains arbitrary OS command execution on the NAS, enabling data theft, file tampering, persistence, and use of the device as a foothold into the internal network.

Attack surface

Reachable over the network via a crafted URL sent to the WSGI server; the CVSS vector (AV:N/PR:L/UI:N) indicates network access with low privileges required and no user interaction.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.602 (99th percentile), indicating high predicted likelihood of exploitation; the vendor advisory is tagged Patch and Vendor Advisory.

What to do

  • Apply the Zyxel security advisory firmware update for NAS326 and NAS542 as the first action.
  • Restrict management and WSGI service access to trusted internal networks; do not expose the NAS to the internet.
  • Enforce strong unique credentials and least-privilege accounts to limit who can reach the post-auth attack path.
  • Monitor NAS accounts for unexpected creation or privilege changes and review device logs for anomalous command activity.
  • If patching is delayed, isolate affected NAS devices on a segmented VLAN with no broad internal reachability.

Detection

  • Alert on crafted or unusual URL patterns and parameters hitting the WSGI server, especially shell metacharacters.
  • Monitor for unexpected child processes spawned by the WSGI/web service on the NAS.
  • Watch for outbound connections from NAS devices to unfamiliar hosts, which may indicate command-and-control or exfiltration.
  • Audit NAS authentication logs for logins from unusual source addresses preceding suspicious activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37928 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27992Zyxel NAS devices pre-auth OS command injectionZyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthentica…KEVEPSS 83%analysed9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2024-6342Zyxel nas326 firmware os command injection vulnerability**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …EPSS 2.1%9.8CVE-2024-29973Zyxel NAS setCookie parameter OS command injectionZyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affe…EPSS 86%analysed9.8CVE-2024-29974Zyxel nas326 firmware unrestricted file upload vulnerability** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…EPSS 23%9.8CVE-2024-29972Zyxel NAS remote_help-cgi unauthenticated OS command injectionThe remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. …EPSS 89%analysed9.8CVE-2023-4473Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C…EPSS 41%9.8CVE-2023-4474Zyxel nas326 firmware os command injection vulnerabilityThe improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …EPSS 30%

Source: NIST National Vulnerability Database (record CVE-2023-37928), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.