Skip to content
COOEY

EXPOSURES › CVE-2020-9054

CVE-2020-9054

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9054 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Zyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code.

A pre-authentication OS command injection vulnerability in Zyxel NAS devices allowed unauthenticated remote attackers to execute arbitrary code, enabling full system compromise. DIB organizations must ensure all network storage devices are patched and monitored, as this flaw was actively exploited in the wild and represents a severe supply-chain and unpatched risk.

Shame score — A pre-auth command injection flaw in widely deployed NAS devices was actively exploited in the wild, representing a severe negligence and unpatched risk that could lead to full system compromise and data breaches.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.