Zyxel NAS Command Injection (CVE-2023-4474)

Related Vulnerabilities: CVE-2023-4474  

Check Point Reference: CPAI-2023-1540 Date Published: 21 Feb 2024 Severity: Critical Last Updated: Wednesday 21 February, 2024 Source: Industry Reference:CVE-2023-4474
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Zyxel NAS326 firmware 5.21(aazf.14)c0 and prior
Zyxel NAS542 firmware 5.21(ABAG.11)C0 and prior Vulnerability Description A command injection vulnerability exists in Zyxel NAS. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands on the affected system.