cbcvebase.
CVE-2023-27992
published 2023-06-19

CVE-2023-27992: The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
84.19%
99.7th percentile
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

Affected

6 ranges
VendorProductVersion rangeFixed in
zyxelnas326_firmware< V5.21(AAZF.14)C0V5.21(AAZF.14)C0
zyxelnas326_firmware< 5.21\(aazf.14\)c05.21\(aazf.14\)c0
zyxelnas540_firmware< V5.21(AATB.11)C0V5.21(AATB.11)C0
zyxelnas540_firmware< 5.21\(aatb.11\)c05.21\(aatb.11\)c0
zyxelnas542_firmware< V5.21(ABAG.11)C0V5.21(ABAG.11)C0
zyxelnas542_firmware< 5.21\(abag.11\)c05.21\(abag.11\)c0

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is exploitable via a crafted HTTP request sent without authentication; monitor for anomalous/malformed HTTP requests targeting Zyxel NAS326, NAS540, and NAS542 devices
  • The vulnerability is pre-authentication, meaning no credentials are required; any HTTP request triggering OS command execution on affected Zyxel NAS devices should be treated as exploitation
  • CVE-2023-27992 is listed in CISA KEV, confirming active exploitation in the wild; prioritize detection on internet-exposed Zyxel NAS devices
  • ·Affected firmware versions are specifically scoped: NAS326 prior to V5.21(AAZF.14)C0, NAS540 prior to V5.21(AATB.11)C0, NAS542 prior to V5.21(ABAG.11)C0 — detections should be scoped to these unpatched versions

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.