Executive brief
Multiple Zyxel NAS devices contain a pre-authentication command injection vulnerability in the weblogin.cgi executable due to improper sanitization of the username parameter. A remote, unauthenticated attacker can execute arbitrary code with root privileges by sending specially crafted HTTP requests. This vulnerability has been observed being exploited in the wild.
Affected products
- Zyxel NAS326 before V5.21(AAZF.7)C0
- Zyxel NAS520 before V5.21(AASZ.3)C0
- Zyxel NAS540 before V5.21(AATB.4)C0
- Zyxel NAS542 before V5.21(ABAG.4)C0
- Zyxel NSA210 All (End-of-Support)
- Zyxel NSA220 All (End-of-Support)
- Zyxel NSA220+ All (End-of-Support)
- Zyxel NSA221 All (End-of-Support)
- Zyxel NSA310 All (End-of-Support)
- Zyxel NSA310S All (End-of-Support)
- Zyxel NSA320 All (End-of-Support)
- Zyxel NSA320S All (End-of-Support)
- Zyxel NSA325 All (End-of-Support)
- Zyxel NSA325v2 All (End-of-Support)
Timeline
- 2020-02-24: disclosed: Public disclosure of 0-day vulnerability
- 2020-03-06: advisory: Initial NVD analysis published
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog