ZeroHour

CVE-2023-27992

KEVniche

Unauthenticated Command Injection in Zyxel NAS326, NAS540, NAS542

CISA: Zyxel Multiple NAS Devices Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

Zyxel NAS326, NAS540, and NAS542 network-attached storage devices contain a pre-authentication command injection flaw (CWE-78) that lets an unauthenticated attacker execute operating system commands by sending a crafted HTTP request to the device. Because the flaw is network-facing and requires no credentials or user interaction, a remote attacker gains the ability to run arbitrary OS commands on the device, effectively full compromise. Affected firmware is NAS326 versions prior to V5.21(AAZF.14)C0, NAS540 versions prior to V5.21(AATB.11)C0, and NAS542 versions prior to V5.21(ABAG.11)C0. The flaw scores 9.8 (critical) on CVSS 3.1, carries a very high 83.8% probability of exploitation within 30 days per EPSS, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23. News reporting indicates a Mirai-like botnet is already exploiting the flaw in the wild, so defenders should treat it as an actively exploited, internet-exposable issue and patch immediately.

What to do: Upgrade NAS326 to V5.21(AAZF.14)C0, NAS540 to V5.21(AATB.11)C0, and NAS542 to V5.21(ABAG.11)C0 per Zyxel's security advisories. Until patched, keep the NAS web administration interface off the public internet or restrict access with firewall rules. Because a Mirai-like botnet is actively exploiting this flaw, inspect patched and unpatched devices for signs of compromise, such as unfamiliar processes or unexpected outbound traffic; organizations covered by CISA's KEV requirements must apply the vendor updates by the required deadline.

Affected
Zyxel NAS326 firmwareall versions prior to V5.21(AAZF.14)C0
Zyxel NAS540 firmwareall versions prior to V5.21(AATB.11)C0
Zyxel NAS542 firmwareall versions prior to V5.21(ABAG.11)C0
Estimated exposure
nichelikely on the order of thousands of internet-exposed devices out of a modest installed base of these three older NAS models (estimate) — The affected products are three discrete, aging consumer/SOHO NAS models rather than a mass-market product line, and NAS web interfaces are commonly exposed directly to the internet, but no public scan counts or install-base figures were…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

CISA Known Exploited Vulnerability
Affected
Zyxel Multiple Network-Attached Storage (NAS) Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
nas326 firmware, nas540 firmware, nas542 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news