CVE-2023-27992
published 2023-06-19CVE-2023-27992: The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
84.19%
99.7th percentile
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | nas326_firmware | < V5.21(AAZF.14)C0 | V5.21(AAZF.14)C0 |
| zyxel | nas326_firmware | < 5.21\(aazf.14\)c0 | 5.21\(aazf.14\)c0 |
| zyxel | nas540_firmware | < V5.21(AATB.11)C0 | V5.21(AATB.11)C0 |
| zyxel | nas540_firmware | < 5.21\(aatb.11\)c0 | 5.21\(aatb.11\)c0 |
| zyxel | nas542_firmware | < V5.21(ABAG.11)C0 | V5.21(ABAG.11)C0 |
| zyxel | nas542_firmware | < 5.21\(abag.11\)c0 | 5.21\(abag.11\)c0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is exploitable via a crafted HTTP request sent without authentication; monitor for anomalous/malformed HTTP requests targeting Zyxel NAS326, NAS540, and NAS542 devices ↗
- →The vulnerability is pre-authentication, meaning no credentials are required; any HTTP request triggering OS command execution on affected Zyxel NAS devices should be treated as exploitation ↗
- →CVE-2023-27992 is listed in CISA KEV, confirming active exploitation in the wild; prioritize detection on internet-exposed Zyxel NAS devices ↗
- ·Affected firmware versions are specifically scoped: NAS326 prior to V5.21(AAZF.14)C0, NAS540 prior to V5.21(AATB.11)C0, NAS542 prior to V5.21(ABAG.11)C0 — detections should be scoped to these unpatched versions ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5wv9-h9hr-4p52: The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5
ghsa_unreviewed·2023-06-19
CVE-2023-27992 [CRITICAL] CWE-78 GHSA-5wv9-h9hr-4p52: The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
VulnCheck
Zyxel Multiple NAS Devices Command Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-27992 [CRITICAL] CWE-78 Zyxel Multiple NAS Devices Command Injection Vulnerability
Zyxel Multiple NAS Devices Command Injection Vulnerability
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
Affected: Zyxel Multiple Network-Attached Storage (NAS) Devices
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-01-07&host_type=src&vulnerability=cve-2023-27992; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-01-10&host_type=src&vulnerability=cve-2023-27992; https://dashboard.shadow
CISA
Zyxel Multiple NAS Devices Command Injection Vulnerability
cisa·2023-06-23·CVSS 9.8
CVE-2023-27992 [CRITICAL] CWE-78 Zyxel Multiple NAS Devices Command Injection Vulnerability
Vulnerability: Zyxel Multiple NAS Devices Command Injection Vulnerability
Affected: Zyxel Multiple Network-Attached Storage (NAS) Devices
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
Required Action: Apply updates per vendor instructions.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products; https://nvd.nist.gov/vuln/detail/CVE-2023-27992
Remediation Due Date: 2023-07-14
No detection rules found.
No public exploits indexed.
Checkpoint
26th June – Threat Intelligence Report
blogs_checkpoint·2023-06-26
CVE-2023-32434 26th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th June – Threat Intelligence Report
Hawaii’s largest university, the University of Hawai’i, has disclosed that one of its campuses had suffered a ransomware attack. The impact of the attack had not been made public by the university, but ransomware gang NoEscape, which has assumed responsibility for the attack, claimed to have exfiltrated 65 GB of sensitive data from the university’s network.
Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.Win.NoEscape)
Af
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise Round-Up: Product Updates
blogs_greynoiseio
GreyNoise Round-Up: Product Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-productshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-productshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27992
2023-06-19
Published
2023-06-23
Added to CISA KEV
Exploited in the wild