ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical Zyxel NAS vulnerabilities patched, update quickly!

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27992
Unauthenticated Command Injection in Zyxel NAS326, NAS540, NAS542

Zyxel NAS326, NAS540, and NAS542 network-attached storage devices contain a pre-authentication command injection flaw (CWE-78) that lets an unauthenticated attacker execute operating system commands by sending a crafted HTTP request to the device. Because the flaw is network-facing and requires no credentials or user interaction, a remote attacker gains the ability to run arbitrary OS commands on the device, effectively full compromise. Affected firmware is NAS326 versions prior to V5.21(AAZF.14)C0, NAS540 versions prior to V5.21(AATB.11)C0, and NAS542 versions prior to V5.21(ABAG.11)C0. The flaw scores 9.8 (critical) on CVSS 3.1, carries a very high 83.8% probability of exploitation within 30 days per EPSS, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23. News reporting indicates a Mirai-like botnet is already exploiting the flaw in the wild, so defenders should treat it as an actively exploited, internet-exposable issue and patch immediately.

Do: Upgrade NAS326 to V5.21(AAZF.14)C0, NAS540 to V5.21(AATB.11)C0, and NAS542 to V5.21(ABAG.11)C0 per Zyxel's security advisories. Until patched, keep the NAS web administration interface off the public internet or restrict access with firewall rules. Because a Mirai-like botnet is actively exploiting this flaw, inspect patched and unpatched devices for signs of compromise, such as unfamiliar processes or unexpected outbound traffic; organizations covered by CISA's KEV requirements must apply the vendor updates by the required deadline.

9.884% KEV
  • Zyxel NAS326 firmware all versions prior to V5.21(AAZF.14)C0
  • Zyxel NAS540 firmware all versions prior to V5.21(AATB.11)C0
  • Zyxel NAS542 firmware all versions prior to V5.21(ABAG.11)C0
nichelikely on the order of thousands of internet-exposed devices out of a modest installed base of these three older NAS models (estimate)
CVE-2023-4473
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could all

A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

NVD description · AI analysis pending
9.8
group max
41%
  • zyxel nas326 firmware
  • zyxel nas542 firmware
Full article393 words · extracted from helpnetsecurity.com · click to collapse

Zyxel has patched six vulnerabilities affecting its network attached storage (NAS) devices, including several (OS) command injection flaws that can be easily exploited by unauthenticated attackers.

Zyxel NAS vulnerabilities

The vulnerabilities in Zyxel NAS devices

One of the six plugged security holes is an improper authentication vulnerability (CVE-2023-35137) in the devices’ authentication module, and may allow unauthenticated attackers to grab system information by sending a specially crafted URL to a vulnerable device.

The remaining five (CVE-2023-35138, CVE-2023-37927, CVE-2023-37928, CVE-2023-4473, CVE-2023-4474) are command injection vulnerabilities in Zyxel NAS devices’ various functions and servers. They may allow either authenticated or unauthenticated attackers to execute some OS commands by simply sending a crafted URL or HTTP POST request to a vulnerable device.

CVE-2023-4473 was discoverd by IBM X-Force researcher Drew Balfour while investigating a previously fixed critical Zyxel NAS bug (CVE-2023-27992).

“During the course of investigating the original issue’s root cause, a new flaw, CVE-2023-4473, and a bypass for the CVE-2023-27992 patch were uncovered. Combined, they allow for pre-authenticated remote code execution on Zyxel NAS devices,” Balfour noted in a blog post published on Thursday, in which he detailed his research.

CVE-2023-27992 has been added to CISA’s Known Exploited Vulnerabilities Catalog on June 23, 2023. According to the agency, it’s still unknown whether it has been used in ransomware campaigns.

What to do?

Zyxel NAS devices are a popular choice with small to medium-sized businesses (SMBs), who use them for data storage, backup, and to enable collaboration.

NAS devices by various manufacturers are often targeted by attackers, who exfiltrate or encrypt data stored on them and hold it for ransom. Attackers have also been known to lay low and exploit the access they have to vulnerable devices to rope them into botnets or use them as a stepping stone for a more thorough compromise of the target’s network.

In 2020, 62,000 QNAP NAS devices across the globe were infected with malware that stole sensitive information, established a backdoor into the system, and persisted on the devices by preventing updates from being installed.

Zyxel does not mention in-the-wild exploitation in their advisory, but urges users to install the patches “for optimal protection.”

Patches are available for NAS326 and NAS542 devices.

UPDATE (December 5, 2023, 05:10 a.m. ET):

Four of the patched vulnerabilities were reported by BugProve researcher Gábor Selján. Technical details are outlined in these vulnerability advisories.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/01/zyxel-nas-vulnerabilities/