← Vulnerability feed

Vulnerability record · CVE-2023-27992 · published 19 June 2023

CVE-2023-27992: Zyxel NAS devices pre-auth OS command injection

Zyxel · Nas326 Firmware

Zyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthenticated remote attacker run operating system commands on the device. Because the devices are network storage holding backups and shared files, compromise exposes both the appliance and the data it stores.

9.8 CVSS 3.1 Critical CISA KEV since 23 Jun 2023 EPSS 83% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-authentication remote command execution with CVSS 9.8, KEV listing and very high EPSS makes this an urgent patch-or-isolate case.

What it is

Zyxel NAS326, NAS540 and NAS542 firmware contain a pre-authentication OS command injection flaw (CWE-78). A crafted HTTP request lets an unauthenticated remote attacker run operating system commands on the device. Because the devices are network storage holding backups and shared files, compromise exposes both the appliance and the data it stores.

Impact

An attacker gains remote code execution as the device's web service, allowing arbitrary OS commands, data theft or destruction, and use of the NAS as a foothold into the internal network.

Attack surface

Reachable over the network via HTTP to the NAS management interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description confirm no authentication and no user interaction are required.

Exploitation

Listed in CISA KEV since 2023-06-23 with a 2023-07-14 remediation due date, and EPSS 30-day probability is about 0.84 (99.7th percentile), indicating active exploitation is expected. No ransomware association is recorded.

What to do

  • Apply the vendor firmware updates: NAS326 V5.21(AAZF.14)C0 or later, NAS540 V5.21(AATB.11)C0 or later, NAS542 V5.21(ABAG.11)C0 or later.
  • If patching cannot be done immediately, remove the NAS management interface from internet exposure and restrict it to trusted internal networks.
  • Segment NAS devices from sensitive systems and limit outbound traffic from them.
  • Change default credentials and disable unused remote management services on the NAS.
  • Monitor vendor advisories for further updates on these end-of-life-adjacent models.

Detection

  • Inspect HTTP request logs to the NAS web interface for command-injection patterns such as shell metacharacters and encoded variants in parameters.
  • Alert on unexpected child processes spawned by the NAS web service (for example shell or command interpreters).
  • Monitor for outbound connections from NAS devices to unfamiliar external hosts.
  • Watch for file integrity changes or unexpected new files in NAS web directories and system paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-27992 to the Known Exploited Vulnerabilities catalog on 23 June 2023 as "Zyxel Multiple NAS Devices Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 14 July 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2024-6342Zyxel nas326 firmware os command injection vulnerability**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 …EPSS 2.1%9.8CVE-2024-29973Zyxel NAS setCookie parameter OS command injectionZyxel NAS326 and NAS542 firmware contain an OS command injection flaw in the setCookie parameter, reachable via a crafted HTTP POST request. The affe…EPSS 86%analysed9.8CVE-2024-29974Zyxel nas326 firmware unrestricted file upload vulnerability** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…EPSS 23%9.8CVE-2024-29972Zyxel NAS remote_help-cgi unauthenticated OS command injectionThe remote_help-cgi CGI program in Zyxel NAS326 and NAS542 firmware mishandles input, allowing OS command injection via a crafted HTTP POST request. …EPSS 89%analysed9.8CVE-2023-4473Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C…EPSS 41%9.8CVE-2023-4474Zyxel nas326 firmware os command injection vulnerabilityThe improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version …EPSS 30%9.8CVE-2023-35138Zyxel nas326 firmware os command injection vulnerabilityA command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firm…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2023-27992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.