Skip to content
COOEY

FAIL › dossier

Multiple Network-Attached Storage (NAS) Devices

PRODUCT

· dossier confidence 80%

Multiple NAS devices suffer from repeated high-severity remote code execution vulnerabilities, indicating a critical need for improved security practices and urgent patching.

PROFILE
CategoryNetwork-Attached Storage (NAS) DevicesWhat they doMultiple Network-Attached Storage (NAS) Devices are a product category providing networked data storage solutions.
SECURITY POSTURE

Needs improvement; recent high severity vulnerabilities indicate a lack of robust security practices.

Notable failures
  • CVE-2023-27992 high RCE on Zyxel NAS
  • CVE-2020-9054 high pre-auth RCE on Zyxel NAS
Patterns: repeated high-severity remote code execution vulnerabilities in NAS firmware
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2020-9054 high Zyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code.
2023-06-23 CVE-2023-27992 high Zyxel NAS devices vulnerable to remote command injection.
Open questions: Are there additional unpatched vulnerabilities in Zyxel NAS devices? · What is the current patching cadence for Zyxel NAS firmware?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:59:56.439024+00:00