CyberSec.Space Logo
返回 CVE 浏览器

CVE-2023-27992

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-06-19
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

Affected Platforms (CPE)

💻
Zyxel

Nas326 Firmware

< 5.21\(aazf.14\)c0
💻
Zyxel

Nas540 Firmware

< 5.21\(aatb.11\)c0
💻
Zyxel

Nas542 Firmware

< 5.21\(abag.11\)c0

References & Advisories

相关漏洞威胁