Description

According to a Zyxel stating to NAS (Network Attached Storage) device customers, the critical command injection flaw, CVE-2023-27992, with a CVSS score of 9.8, could allow hackers to execute operating system commands by sending specially crafted HTTP requests, affecting the NAS326, NAS540, and NAS542. Users are advised to apply security fixes because Zyxel has not disclosed any remedies to address the issue. The complex nature of the malicious HTTP request and other criteria for exploiting the new vulnerabilities are unknown at this time, although the lack of authentication makes the issue easier to attack. Hackers are constantly looking for severe Zyxel flaws that may be exploited remotely and are fast to use publicly disclosed PoC exploits to attack unpatched devices. Ransomware groups target NAS equipment in particular, exploiting flaws remotely to encrypt files and issue ransom demands.