Home/Product/zyxel nas542 firmware
Product

zyxel nas542 firmware

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-6342
< 5.21\(abag.15\)c0
UNSUPPORTED WHEN ASSIGNED A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions throug
9.8CRITICAL
CVE-2024-29976
< 5.21\(abag.14\)c0
UNSUPPORTED WHEN ASSIGNED The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS
6.5MEDIUM
CVE-2024-29975
< 5.21\(abag.14\)c0
UNSUPPORTED WHEN ASSIGNED The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firm
6.7MEDIUM
CVE-2024-29974
< 5.21\(abag.14\)c0
UNSUPPORTED WHEN ASSIGNED The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 f
9.8CRITICAL
CVE-2024-29973
< 5.21\(abag.14\)c0
UNSUPPORTED WHEN ASSIGNED The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware vers
9.8CRITICAL
CVE-2024-29972
< 5.21\(abag.14\)c0
UNSUPPORTED WHEN ASSIGNED The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware
9.8CRITICAL
CVE-2023-5372
< 5.21\(abag.13\)c0
The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firm
7.2HIGH
CVE-2023-4474
<= 5.21\(abag.11\)c0
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS54
9.8CRITICAL
CVE-2023-4473
<= 5.21\(abag.11\)c0
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware vers
9.8CRITICAL
CVE-2023-37928
<= 5.21\(abag.11\)c0
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and
8.8HIGH
CVE-2023-37927
<= 5.21\(abag.11\)c0
The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS54
8.8HIGH
CVE-2023-35138
<= 5.21\(abag.11\)c0
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZ
9.8CRITICAL
CVE-2023-35137
<= 5.21\(abag.11\)c0
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NA
7.5HIGH
CVE-2023-27992
< 5.21\(abag.11\)c0
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 fi
9.8CRITICAL
CVE-2023-27988
< 5.21\(abag.10\)c0
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allo
7.2HIGH
CVE-2020-13365
< v5.21\(abag.6\)c0
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented use
8.8HIGH
CVE-2020-13364
< v5.21\(abag.6\)c0
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ
8.8HIGH
CVE-2020-9054
< 5.21\(abag.4\)c0
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin