Vulnerability record · CVE-2023-27992 · published 19 June 2023
CVE-2023-27992: Zyxel NAS devices pre-auth OS command injection
Zyxel · Nas326 Firmware
Zyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthenticated remote attacker run operating system commands on the device. Because the devices are network storage holding backups and shared files, compromise exposes both the appliance and the data it stores.
Description
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication remote command execution with CVSS 9.8, KEV listing and very high EPSS makes this an urgent patch-or-isolate case.
What it is
Zyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthenticated remote attacker run operating system commands on the device. Because the devices are network storage holding backups and shared files, compromise exposes both the appliance and the data it stores.
Impact
An attacker gains remote code execution as the device's web service, allowing arbitrary OS commands, data theft or destruction, and use of the NAS as a foothold into the internal network.
Attack surface
Reachable over the network via HTTP to the NAS management interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description confirm no authentication and no user interaction are required.
Exploitation
Listed in CISA KEV since 2023-06-23 with a 2023-07-14 remediation due date, and EPSS 30-day probability is about 0.84 (99.7th percentile), indicating active exploitation is expected. No ransomware association is recorded.
What to do
- Apply the vendor firmware updates: NAS326 V5.21(AAZF.14)C0 or later, NAS540 V5.21(AATB.11)C0 or later, NAS542 V5.21(ABAG.11)C0 or later.
- If patching cannot be done immediately, remove the NAS management interface from internet exposure and restrict it to trusted internal networks.
- Segment NAS devices from sensitive systems and limit outbound traffic from them.
- Change default credentials and disable unused remote management services on the NAS.
- Monitor vendor advisories for further updates on these end-of-life-adjacent models.
Detection
- Inspect HTTP request logs to the NAS web interface for command-injection patterns such as shell metacharacters and encoded variants in parameters.
- Alert on unexpected child processes spawned by the NAS web service (for example shell or command interpreters).
- Monitor for outbound connections from NAS devices to unfamiliar external hosts.
- Watch for file integrity changes or unexpected new files in NAS web directories and system paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-27992 to the Known Exploited Vulnerabilities catalog on 23 June 2023 as "Zyxel Multiple NAS Devices Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 July 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-27992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.