ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Zyxel patches critical vulnerability in NAS devices (CVE-2023-27992)

criticalVulnerability exploited in the wildimportance 60CVE-2023-27992

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27992
Unauthenticated Command Injection in Zyxel NAS326, NAS540, NAS542

Zyxel NAS326, NAS540, and NAS542 network-attached storage devices contain a pre-authentication command injection flaw (CWE-78) that lets an unauthenticated attacker execute operating system commands by sending a crafted HTTP request to the device. Because the flaw is network-facing and requires no credentials or user interaction, a remote attacker gains the ability to run arbitrary OS commands on the device, effectively full compromise. Affected firmware is NAS326 versions prior to V5.21(AAZF.14)C0, NAS540 versions prior to V5.21(AATB.11)C0, and NAS542 versions prior to V5.21(ABAG.11)C0. The flaw scores 9.8 (critical) on CVSS 3.1, carries a very high 83.8% probability of exploitation within 30 days per EPSS, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23. News reporting indicates a Mirai-like botnet is already exploiting the flaw in the wild, so defenders should treat it as an actively exploited, internet-exposable issue and patch immediately.

Do: Upgrade NAS326 to V5.21(AAZF.14)C0, NAS540 to V5.21(AATB.11)C0, and NAS542 to V5.21(ABAG.11)C0 per Zyxel's security advisories. Until patched, keep the NAS web administration interface off the public internet or restrict access with firewall rules. Because a Mirai-like botnet is actively exploiting this flaw, inspect patched and unpatched devices for signs of compromise, such as unfamiliar processes or unexpected outbound traffic; organizations covered by CISA's KEV requirements must apply the vendor updates by the required deadline.

9.884% KEV
  • Zyxel NAS326 firmware all versions prior to V5.21(AAZF.14)C0
  • Zyxel NAS540 firmware all versions prior to V5.21(AATB.11)C0
  • Zyxel NAS542 firmware all versions prior to V5.21(ABAG.11)C0
nichelikely on the order of thousands of internet-exposed devices out of a modest installed base of these three older NAS models (estimate)
Full article147 words · extracted from helpnetsecurity.com · click to collapse

Zyxel has released firmware patches for a critical vulnerability (CVE-2023-27992) in some of its consumer network attached storage (NAS) devices.

CVE-2023-27992

About CVE-2023-27992

CVE-2023-27992 is an OS command injection flaw that could be triggered remotely by an unauthenticated attacker, via a specially crafted HTTP request.

It affects the following Zyxel NAS devices:

  • NAS326 – firmware versions prior to V5.21(AAZF.14)C0
  • NAS540 – firmware versions prior to V5.21(AATB.11)C0
  • NAS542 – firmware versions prior to V5.21(ABAG.11)C0

Andrej Zaujec, National Cyber Security Centre Finland (NCSC-FI), and Maxim Suslov have been credited with reporting the vulnerability.

Patch quickly!

NAS devices are often targeted by attackers wielding specialized ransomware and malware such as the Mirai bot (and variants).

There is currently no indication that CVE-2023-27992 is being actively exploited. Since Zyxel does not mention workarounds or mitigations, owners/admins of the aforementioned NAS device models are advised to quickly upgrade to the latest firmware version.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/06/20/cve-2023-27992/