← Vulnerability feed

Vulnerability record · CVE-2023-4473 · published 30 November 2023

CVE-2023-4473: Zyxel nas326 firmware os command injection vulnerability

Zyxel · Nas326 Firmware

A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

9.8 CVSS 3.1 Critical EPSS 41% · top 1.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score
41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-4473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27992Zyxel NAS devices pre-auth OS command injectionZyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthentica…KEVEPSS 83%analysed9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2024-6342Zyxel nas326 firmware os command injection vulnerability**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …EPSS 2.1%9.8CVE-2024-29973Zyxel NAS setCookie parameter OS command injectionZyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affe…EPSS 86%analysed9.8CVE-2024-29974Zyxel nas326 firmware unrestricted file upload vulnerability** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…EPSS 23%9.8CVE-2024-29972Zyxel NAS remote_help-cgi unauthenticated OS command injectionThe remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. …EPSS 89%analysed9.8CVE-2023-4474Zyxel nas326 firmware os command injection vulnerabilityThe improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …EPSS 30%9.8CVE-2023-35138Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2023-4473), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.