Loading HuntDB...

Zyxel Multiple NAS Devices Command Injection Vulnerability

Added June 23, 2023 Due July 14, 2023 CVE-2023-27992
Overdue Zyxel / Multiple Network-Attached Storage (NAS) Devices CWE-78

Description

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
4 months, 2 weeks ago