CVE-2023-27992 - Zyxel Multiple NAS Devices Command Injection Vulnerability
项目:Zyxel
产品:Multiple Network-Attached Storage (NAS) Devices
添加日期:2023-06-23到期日:2023-07-14最后更新:June 21, 2025
漏洞名称
Zyxel Multiple NAS Devices Command Injection Vulnerability
描述
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
已知用于勒索软件活动吗?
Unknown
采集行动
Apply updates per vendor instructions.
其他说明
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
https://nvd.nist.gov/vuln/detail/CVE-2023-27992