EXPOSURES › CVE-2023-27992
CVE-2023-27992
HIGH ⌖ ON CISA KEV · EXPLOITEDZyxel NAS devices vulnerable to remote command injection.
Zyxel's multiple network-attached storage (NAS) devices are vulnerable to a pre-authentication command injection vulnerability, allowing remote command execution via crafted HTTP requests. This poses a significant risk to organizations using these devices, as it can be exploited without authentication. Immediate patching is recommended to mitigate this high-risk vulnerability.
Shame score — Zyxel's history of releasing products with critical vulnerabilities, coupled with the high severity of the command injection flaw, indicates a significant lapse in security posture and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.