SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-27992

Zyxel Multiple NAS Devices Command Injection Vulnerability

KEVCRITICAL 9.8EPSS 83.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 14 July 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
83.79% probability · 100th percentile
CISA KEV
Listed 23 June 2023 · due 14 July 2023
Weakness
CWE-78
Affected
zyxel/nas326 firmware · zyxel/nas540 firmware · zyxel/nas542 firmware
Source
security@zyxel.com.tw

CISA notes

Apply updates per vendor instructions. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products; https://nvd.nist.gov/vuln/detail/CVE-2023-27992

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.