EXPOSURES › CVE-2020-9054
CVE-2020-9054
HIGH ⌖ ON CISA KEV · EXPLOITEDZyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code.
A pre-authentication OS command injection vulnerability in Zyxel NAS devices allowed unauthenticated remote attackers to execute arbitrary code, enabling full system compromise. DIB organizations must ensure all network storage devices are patched and monitored, as this flaw was actively exploited in the wild and represents a severe supply-chain and unpatched risk.
Shame score — A pre-auth command injection flaw in widely deployed NAS devices was actively exploited in the wild, representing a severe negligence and unpatched risk that could lead to full system compromise and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.