OS Command Injection in ZyXEL Communications Corp. products - CVE-2020-9054
Published: February 25, 2020 / Updated: October 9, 2023
Zyxel NAS 326
NAS520
NAS540
NAS542
NSA210
NSA220
NSA220+
NSA221
NSA310
NSA310S
NSA320
NSA320S
NSA325
NSA325v2
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing username in the login form. A remote unauthenticated attacker can send a specially crafted HTTP request and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2020-9054
The vendor has released a hotfix for the following models:
- NAS326
- NAS520
- NAS540
- NAS542