Zyxel Nas520 Firmware vulnerabilities
3 known vulnerabilities affecting zyxel/nas520_firmware.
Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-13364HIGHCVSS 8.8fixed in v5.21\(aasz.5\)c02020-08-06
CVE-2020-13364 [HIGH] CVE-2020-13364: A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS5
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)
nvd
CVE-2020-13365HIGHCVSS 8.8fixed in v5.21\(aasz.5\)c02020-08-06
CVE-2020-13365 [HIGH] CWE-287 CVE-2020-13365: Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a pa
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4
nvd
CVE-2020-9054CRITICALCVSS 9.8KEVPoCfixed in 5.21\(aasz.3\)c02020-03-04
CVE-2020-9054 [CRITICAL] CWE-78 CVE-2020-9054: Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-au
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to
nvd