FAIL › dossier
Multiple Network-Attached Storage (NAS) Devices
PRODUCT· dossier confidence 80%
Multiple NAS devices suffer from repeated high-severity remote code execution vulnerabilities, indicating a critical need for improved security practices and urgent patching.
PROFILE
CategoryNetwork-Attached Storage (NAS) DevicesWhat they doMultiple Network-Attached Storage (NAS) Devices are a product category providing networked data storage solutions.
SECURITY POSTURE
Needs improvement; recent high severity vulnerabilities indicate a lack of robust security practices.
Notable failures
- CVE-2023-27992 high RCE on Zyxel NAS
- CVE-2020-9054 high pre-auth RCE on Zyxel NAS
Patterns: repeated high-severity remote code execution vulnerabilities in NAS firmware
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2020-9054 | high | Zyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code. |
| 2023-06-23 | CVE-2023-27992 | high | Zyxel NAS devices vulnerable to remote command injection. |
Open questions: Are there additional unpatched vulnerabilities in Zyxel NAS devices? · What is the current patching cadence for Zyxel NAS firmware?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 03:59:56.439024+00:00