CVE-2023-27992—Zyxel Multiple NAS Devices Command Injection Vulnerability
PUBLISHEDvulnerability record
2023-06-23 · last modified June 21, 2025
Metadata
Vulnerability Name
Zyxel Multiple NAS Devices Command Injection Vulnerability
Description
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.