LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 23, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 14, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-27992 to its Known Exploited Vulnerabilities catalog on Jun 23, 2023, with a federal patch deadline of Jul 14, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a…

CVE-2023-27992 is a pre-authentication command injection flaw affecting multiple Zyxel network-attached storage (NAS) devices. An unauthenticated attacker can send a crafted HTTP request that causes the device to execute arbitrary commands with the privileges of the vulnerable service. Because NAS appliances often hold shared files, backups, and credentials and are commonly reachable from the network, successful exploitation can lead to full device compromise, data theft, or use of the host as a foothold into the rest of the environment. Confirm exact product coverage and fixed firmware against the vendor advisory.

How it works

The vulnerability is classified as CWE-78 (OS Command Injection). In this class of flaw, user-controlled input that reaches a shell or system command is not properly sanitized or escaped. On the affected Zyxel NAS devices, an attacker who can reach the HTTP interface can craft a request that injects additional shell metacharacters or commands. Because the injection occurs before authentication, no valid credentials are required. Once the injected command runs, the attacker can typically achieve remote code execution at the privilege level of the web or management process. Specific request parameters, payloads, or exact execution context are not detailed here; defenders must consult the vendor advisory for any technical indicators that have been published.

Am I affected? How to find it in your systems

Zyxel NAS devices are typically deployed as file servers, backup targets, or media storage on corporate, branch, or home networks. They may be exposed on internal LANs, DMZs, or, less securely, directly to the internet via port forwarding or UPnP.

How to remediate

The primary remediation is to apply the firmware updates published by Zyxel for the affected NAS models, following the vendor’s installation instructions exactly. CISA’s required action is simply to apply updates per vendor instructions. After patching:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a pre-authentication remote command-injection flaw:

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on storage devices frequently lead to data breaches or ransomware deployment, even though ransomware use specifically tied to this CVE is not documented. If you suspect compromise, isolate the device, preserve forensic images and logs, and examine shared volumes for unauthorized access or encryption. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or personal information associated with the environment have already appeared in public dumps. Follow your incident-response plan for containment, eradication, and recovery, and treat any recovered credentials as compromised.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · Multiple Network-Attached Storage (NAS) Devices
WeaknessCWE-78
Added to CISA KEVJun 23, 2023
Federal patch deadlineJul 14, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities