CVE-2023-27992
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 83%
- Percentile among all scored CVEs: 100
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 6/23/2023
- Remediation due date: 7/14/2023
- Known ransomware use: Unknown
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access95 % - Primary impact
T1059Command and Scripting Interpreterexecution95 %
Inyección de comandos preautenticación en servidor NAS accesible remotamente (AV:N, PR:N). CWE-78 y descripción confirman ejecución de comandos OS.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (3)
CWEs
- CWE-78
- CWE-78
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27992
Raw JSON (NVD)
Show
{
"id": "CVE-2023-27992",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-27992",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-27T22:16:42.703923Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@zyxel.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@zyxel.com.tw",
"affectedData": [
{
"vendor": "Zyxel",
"product": "NAS326 firmware",
"versions": [
{
"status": "affected",
"version": "< V5.21(AAZF.14)C0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Zyxel",
"product": "NAS540 firmware",
"versions": [
{
"status": "affected",
"version": "< V5.21(AATB.11)C0"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Zyxel",
"product": "NAS542 firmware",
"versions": [
{
"status": "affected",
"version": "< V5.21(ABAG.11)C0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-06-19T12:15:09.433",
"references": [
{
"url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security@zyxel.com.tw"
},
{
"url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27992",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@zyxel.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request."
}
],
"lastModified": "2026-06-17T05:46:20.047",
"cisaActionDue": "2023-07-14",
"cisaExploitAdd": "2023-06-23",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nas326_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4A72863-E165-4A25-B53F-EE5F97236C5A",
"versionEndExcluding": "5.21\\(aazf.14\\)c0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nas326:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0A01B19-4A91-4FBC-8447-2E854346DAC5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nas540_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E86737DF-B02E-484D-AFB8-00D4F3B15330",
"versionEndExcluding": "5.21\\(aatb.11\\)c0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nas540:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B2F7264C-D32A-4EE9-BADC-78518D762BCA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:zyxel:nas542_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DB6182FF-5301-474F-B324-651208839B0F",
"versionEndExcluding": "5.21\\(abag.11\\)c0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:zyxel:nas542:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "31C4DD0F-28D0-4BF7-897B-5EEC32AA7277"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@zyxel.com.tw",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Zyxel Multiple NAS Devices Command Injection Vulnerability"
}