LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-9054: Zyxel Multiple NAS Devices OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-9054 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

CVE-2020-9054 is a pre-authentication OS command injection flaw affecting multiple Zyxel network-attached storage (NAS) devices. A remote attacker who can reach the device over the network may be able to execute arbitrary code without valid credentials. Because NAS systems often hold shared files, backups, and credentials, successful abuse can lead to data theft, ransomware staging, or further movement inside the network. Confirm exact product coverage and fixed builds against the vendor advisory.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In products of this class, user-controlled input is passed to a system shell or command interpreter without adequate sanitization or parameterization. When the vulnerable interface is reachable before authentication, an unauthenticated attacker can supply crafted input that the device interprets as operating-system commands. Those commands then run with the privileges of the affected service, which on many NAS appliances is high enough to read or alter stored data and install persistence. Public detail on the precise injection point and request format is limited; treat any internet-facing management or file-service endpoint on an affected Zyxel NAS as potentially exploitable until the vendor patch is applied and verified.

Am I affected? How to find it in your systems

Zyxel NAS appliances are commonly deployed in small-to-medium business and branch offices for file sharing, backup targets, and media storage. They may sit on internal LANs, DMZs, or—less ideally—directly on the internet with ports forwarded for remote access.

How to remediate

Patching is the primary fix. Apply the firmware updates published by Zyxel for the specific models covered by CVE-2020-9054, following the vendor’s installation instructions and any required reboot or verification steps. After updating, re-check the running firmware version to confirm the fix is active.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These measures lower likelihood and impact but do not replace the firmware update.

If your data may have been exposed

Actively exploited pre-authentication vulnerabilities on internet-reachable NAS devices have led to data theft and follow-on compromise in other incidents. If logs or external notifications suggest your Zyxel NAS was targeted, isolate the device, preserve forensic images and logs, rotate credentials that may have been stored or cached on it, and restore data from known-good backups after verifying integrity. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in public breach corpora, then force password resets and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · Multiple Network-Attached Storage (NAS) Devices
WeaknessCWE-78
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities