Executive brief
Multiple Zyxel NAS devices contain a pre-authentication command injection vulnerability in their firmware. An unauthenticated remote attacker can execute arbitrary operating system commands by sending a specially crafted HTTP request to the affected device.
Affected products
- Zyxel NAS326 firmware prior to V5.21(AAZF.14)C0
- Zyxel NAS540 firmware prior to V5.21(AATB.11)C0
- Zyxel NAS542 firmware prior to V5.21(ABAG.11)C0
Timeline
- 2023-06-19: disclosed: NVD Published Date
- 2023-06-23: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-23: exploited: Reported as exploited in the wild