CVE-2023-4474: OS Command Injection
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4474?
CVE-2023-4474 is a vulnerability that allows an unauthenticated attacker to execute operating system commands on a Zyxel NAS326 or NAS542 device.
What is the severity of CVE-2023-4474?
CVE-2023-4474 has a severity rating of 9.8, which is considered critical.
Which products are affected by CVE-2023-4474?
The Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 are affected.
How can an attacker exploit CVE-2023-4474?
An attacker can exploit CVE-2023-4474 by sending a crafted URL to a vulnerable Zyxel NAS326 or NAS542 device.
Is authentication required to exploit CVE-2023-4474?
No, CVE-2023-4474 allows an unauthenticated attacker to execute operating system commands.