CVE-2023-35138
published 2023-11-30CVE-2023-35138: A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware…
PriorityP183critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
40.00%
98.5th percentile
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | nas326_firmware | <= 5.21\(aazf.14\)c0 | — |
| zyxel | nas326_firmware | — | — |
| zyxel | nas542_firmware | <= 5.21\(abag.11\)c0 | — |
| zyxel | nas542_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Checkpoint
4th December – Threat Intelligence Report
blogs_checkpoint·2023-12-04·CVSS 7.5
CVE-2023-4966 [HIGH] 4th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 4th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 4th December, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Check Point Research provides highlights about Cyber Av3ngers group activity, which has taken responsibility on defacing workstations at Pennsylvania’s Aliquippa municipal water authority. Following the attack, CISA has published an advisory about this hacktivists group which is affiliated to Iranian Revolutionary Guard C
Bleepingcomputer
Zyxel warns of multiple critical vulnerabilities in NAS devices
blogs_bleepingcomputer·2023-11-30·CVSS 7.5
[HIGH] Zyxel warns of multiple critical vulnerabilities in NAS devices
## Zyxel warns of multiple critical vulnerabilities in NAS devices
## Bill Toulas
Zyxel has addressed multiple security issues, including three critical ones that could allow an unauthenticated attacker to execute operating system commands on vulnerable network-attached storage (NAS) devices.
Zyxel NAS systems are used for storing data in a centralized location on the network. They are designed for high volumes of data and offer features like data backup, media streaming, or customized sharing options.
Typical Zyxel NAS users include small to medium-sized businesses seeking a solution that combines data management, remote work, and collaboration features, as well as IT professionals setting up data redundancy systems, or videographers and digital artists working with large files.
In a
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-productshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products
2023-11-30
Published