CVE-2023-27992 - Zyxel Multiple NAS Devices Command Injection Vulnerability

项目:Zyxel

产品:Multiple Network-Attached Storage (NAS) Devices

添加日期:2023-06-23到期日:2023-07-14最后更新:June 21, 2025

漏洞名称

Zyxel Multiple NAS Devices Command Injection Vulnerability

描述

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.

已知用于勒索软件活动吗?

Unknown

采集行动

Apply updates per vendor instructions.

其他说明

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products

https://nvd.nist.gov/vuln/detail/CVE-2023-27992

相关 CWE