cbcvebase.
CVE-2023-4474
published 2023-11-30

CVE-2023-4474: The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version…

PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
29.74%
98.0th percentile
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

Affected

4 ranges
VendorProductVersion rangeFixed in
zyxelnas326_firmware<= 5.21\(aazf.14\)c0
zyxelnas326_firmware
zyxelnas542_firmware<= 5.21\(abag.11\)c0
zyxelnas542_firmware

Detection & IOCsextracted from sources · hover to see the quote

path/cmd,/ck6fup6/time_machine_main/setTimeMachineStatus
path/cmd,/ck6fup6/zylog_main/show_logging_entries/
path/cmd,/ck6fup6/zylog_main/configure_mail_syslog/
path/cmd,/ck6fup6/portal_main/pkg_init_cmd/
path/cmd,/ck6fup6/
path/cmd,/ck6fup6/system_main/show_sysinfo/
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M6"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/time_machine_main/setTimeMachineStatus"; fast_pattern; startswith; pcre:"/(?:target_share|share_name)\x3d.*\x3b/R"; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4474; reference:cve,2024-4474; classtype:attempted-admin; sid:2052367; rev:1;)
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M2"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/zylog_main/show_logging_entries/"; fast_pattern; startswith; content:"type|3d|"; distance:0; content:"|3b|"; within:100; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4474; reference:cve,2024-4474; classtype:attempted-admin; sid:2052363; rev:1;)
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M3"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/zylog_main/configure_mail_syslog/"; fast_pattern; startswith; pcre:"/(?:mailTo|mailFrom|mailServer|mailFormat|accountSMTP|passwdSMTP|scheduleDay|scheduleHour|scheduleMinute)\x3d.*\x3b/R"; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4474; reference:cve,2024-4474; classtype:attempted-admin; sid:2052364; rev:1;)
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Command Injection Attempt (CVE-2024-4474) M1"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/portal_main/pkg_init_cmd/"; fast_pattern; startswith; content:"pkgname|3d|"; distance:0; content:"cmd|3d|"; within:100; content:"|3b|"; within:100; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4474; reference:cve,2024-4474; classtype:attempted-admin; sid:2052362; rev:1;)
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Authentication Bypass Attempt (CVE-2023-4473)"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/"; fast_pattern; startswith; pcre:"/\/(?:favicon.ico|adv,\/cgi-bin\/weblogin\.cgi|desktop,\/(?:file_download\.cgi|cgi-bin\/dlnotify|login\.html|res\/|css\/|utility\/flag\/js)|MyWeb\/|register_main\/setCookie|playzone,\/(?:mobile_login\.html|mobile\/sencha\/|mobile\/images\/|images\/))/R"; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4473; classtype:attempted-admin; sid:2052325; rev:3;)
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel Authentication Bypass Attempt (CVE-2023-4473) - Information Leak via show_sysinfo"; flow:established,to_server; http.uri; content:"/cmd,/ck6fup6/system_main/show_sysinfo/"; fast_pattern; startswith; pcre:"/(?:favicon.ico|adv,\/cgi-bin\/weblogin\.cgi|desktop,\/(?:file_download\.cgi|cgi-bin\/dlnotify|login\.html|res\/|css\/|utility\/flag\/js)|MyWeb\/|register_main\/setCookie|playzone,\/(?:mobile_login\.html|mobile\/sencha\/|mobile\/images\/|images\/))/R"; reference:url,bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/; reference:cve,2023-4473; classtype:attempted-admin; sid:2052326; rev:2;)
  • Command injection payloads in URI parameters are identified by a semicolon (;, hex 0x3b) following parameter values — look for URI parameters such as target_share, share_name, type, mailTo, mailFrom, mailServer, pkgname, cmd containing a semicolon as a shell injection delimiter.
  • For the pkg_init_cmd endpoint, injection is signalled by the presence of both 'pkgname=' and 'cmd=' parameters followed by a semicolon (0x3b) within 100 bytes — monitor HTTP URIs matching this pattern.
  • For the show_logging_entries endpoint, injection is signalled by a 'type=' parameter followed by a semicolon (0x3b) within 100 bytes in the URI.
  • For the configure_mail_syslog endpoint, injection is signalled by mail/schedule-related parameters (mailTo, mailFrom, mailServer, mailFormat, accountSMTP, passwdSMTP, scheduleDay, scheduleHour, scheduleMinute) followed by a semicolon in the URI.
  • The authentication bypass (CVE-2023-4473) abuses the WSGI path prefix /cmd,/ck6fup6/ — any HTTP request with a URI starting with this prefix and matching known bypass sub-paths (e.g., favicon.ico, weblogin.cgi, login.html, setCookie) should be treated as suspicious.
  • The vulnerability is exploitable by unauthenticated attackers via a crafted URL to the WSGI server — prioritize perimeter and internal network monitoring for these URI patterns on HTTP traffic.
  • ·Affected firmware versions are specifically NAS326 V5.21(AAZF.14)C0 and NAS542 V5.21(ABAG.11)C0 — detections should be scoped to these device types and versions where asset inventory is available.
  • ·The Snort/ET rules are marked tls_state plaintext — these signatures will NOT fire on TLS-encrypted traffic; ensure inspection is performed on plaintext HTTP sessions only.
  • ·The ET rules reference both CVE-2023-4474 and CVE-2024-4474 — verify the correct CVE mapping for your environment, as the rule metadata may conflate two distinct CVE identifiers.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.