CVE-2023-27988: OS Command Injection
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device remotely.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-27988?
CVE-2023-27988 is a post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0.
What can an attacker do with CVE-2023-27988?
An authenticated attacker with administrator privileges can execute operating system commands on an affected device remotely.
How can I fix CVE-2023-27988?
Update the Zyxel NAS326 firmware to version V5.21(AAZF.13)C0 or later.
Is Zyxel Nas326 firmware version 5.21(AAZF.13)C0 affected by CVE-2023-27988?
No, Zyxel Nas326 firmware version 5.21(AAZF.13)C0 or later is not vulnerable to CVE-2023-27988.
Where can I find more information about CVE-2023-27988?
You can find more information about CVE-2023-27988 in the Zyxel security advisory for the post-authentication command injection vulnerability in NAS products. The advisory is available at: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-post-authentication-command-injection-vulnerability-in-nas-products