Junglewise Threat Intelligence

CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerability

CVE-2023-27992 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-23

Vendors: Zyxel.

Executive brief

Multiple Zyxel NAS devices contain a pre-authentication command injection vulnerability in their firmware. An unauthenticated remote attacker can execute arbitrary operating system commands by sending a specially crafted HTTP request to the affected device.

Affected products

  • Zyxel NAS326 firmware prior to V5.21(AAZF.14)C0
  • Zyxel NAS540 firmware prior to V5.21(AATB.11)C0
  • Zyxel NAS542 firmware prior to V5.21(ABAG.11)C0

Timeline

  • 2023-06-19: disclosed: NVD Published Date
  • 2023-06-23: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-23: exploited: Reported as exploited in the wild

Related threats