cbcvebase.
CVE-2023-35138
published 2023-11-30

CVE-2023-35138: A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware…

PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
40.00%
98.5th percentile
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

Affected

4 ranges
VendorProductVersion rangeFixed in
zyxelnas326_firmware<= 5.21\(aazf.14\)c0
zyxelnas326_firmware
zyxelnas542_firmware<= 5.21\(abag.11\)c0
zyxelnas542_firmware
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.