Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-5372
HistoryJan 30, 2024 - 1:15 a.m.

Command injection

2024-01-3001:15:00
PRIOn knowledge base
www.prio-n.com
7
post-authentication
command injection
zyxel nas326
nas542
firmware
vulnerability
authenticated attacker
administrator privileges
operating system commands
web management interface

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.7%

The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands by sending a crafted query parameter attached to the URL of an affected device’s web management interface.

7.9 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.7%

Related for PRION:CVE-2023-5372