Junglewise Threat Intelligence

CVE-2020-9054: Zyxel Multiple NAS Devices OS Command Injection Vulnerability

CVE-2020-9054 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Zyxel.

Executive brief

Multiple Zyxel NAS devices contain a pre-authentication command injection vulnerability in the weblogin.cgi executable due to improper sanitization of the username parameter. A remote, unauthenticated attacker can execute arbitrary code with root privileges by sending specially crafted HTTP requests. This vulnerability has been observed being exploited in the wild.

Affected products

  • Zyxel NAS326 before V5.21(AAZF.7)C0
  • Zyxel NAS520 before V5.21(AASZ.3)C0
  • Zyxel NAS540 before V5.21(AATB.4)C0
  • Zyxel NAS542 before V5.21(ABAG.4)C0
  • Zyxel NSA210 All (End-of-Support)
  • Zyxel NSA220 All (End-of-Support)
  • Zyxel NSA220+ All (End-of-Support)
  • Zyxel NSA221 All (End-of-Support)
  • Zyxel NSA310 All (End-of-Support)
  • Zyxel NSA310S All (End-of-Support)
  • Zyxel NSA320 All (End-of-Support)
  • Zyxel NSA320S All (End-of-Support)
  • Zyxel NSA325 All (End-of-Support)
  • Zyxel NSA325v2 All (End-of-Support)

Timeline

  • 2020-02-24: disclosed: Public disclosure of 0-day vulnerability
  • 2020-03-06: advisory: Initial NVD analysis published
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats