logo

Vulnerability in Zyxel Network Attached Storage (NAS) Devices

ID: 7aac1b79-8f04-5d13-b1ae-351966e2b7ac

STIX ID: report--7aac1b79-8f04-5d13-b1ae-351966e2b7ac

Feed Name: FortiGuard Threat Signals

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-07-28

...
...

FortiGuard Labs summarizes a CERT/CC advisory for CVE-2020-9054: a pre-authentication command injection in Zyxel NAS devices (weblogin.cgi) allowing unauthenticated remote code execution with potential root escalation. The advisory lists affected models (NAS326/NAS520/NAS540/NAS542), notes public exploit code and a CVSS score of 10, and points to Zyxel firmware updates (March 2020) and recommended network mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.