← Back to CVE List

CVE-2023-37928

Published: 2023-11-30T02:15Z
Last Modified: 2024-11-21T08:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt