CVE Feed

    Dashboard / CVE / CVE-2020-9054

    CVE-2020-9054

    Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

    Published:Mar 4, 2020
    Last Modified:Nov 10, 2025
    EPS:Mar 4, 2020
    EPSS Score:0.94312
    CVSS Score:9.8

    CISA Notification

    Description

    Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Apr 15, 2022
    1610 days ago
    Alert Date
    Mar 25, 2022
    1631 days ago

    Affected Products

    Vendor
    Zyxel
    Product
    Atp100
    Vendor
    Zyxel
    Product
    Atp100 Firmware
    Vendor
    Zyxel
    Product
    Atp200
    Vendor
    Zyxel
    Product
    Atp200 Firmware
    Vendor
    Zyxel
    Product
    Atp500
    Vendor
    Zyxel
    Product
    Atp500 Firmware
    Vendor
    Zyxel
    Product
    Atp800
    Vendor
    Zyxel
    Product
    Atp800 Firmware
    Vendor
    Zyxel
    Product
    Nas326
    Vendor
    Zyxel
    Product
    Nas326 Firmware
    Vendor
    Zyxel
    Product
    Nas520
    Vendor
    Zyxel
    Product
    Nas520 Firmware
    Vendor
    Zyxel
    Product
    Nas540
    Vendor
    Zyxel
    Product
    Nas540 Firmware
    Vendor
    Zyxel
    Product
    Nas542
    Vendor
    Zyxel
    Product
    Nas542 Firmware
    Vendor
    Zyxel
    Product
    Usg110
    Vendor
    Zyxel
    Product
    Usg1100
    Vendor
    Zyxel
    Product
    Usg1100 Firmware
    Vendor
    Zyxel
    Product
    Usg110 Firmware
    Vendor
    Zyxel
    Product
    Usg1900
    Vendor
    Zyxel
    Product
    Usg1900 Firmware
    Vendor
    Zyxel
    Product
    Usg20-vpn
    Vendor
    Zyxel
    Product
    Usg20-vpn Firmware
    Vendor
    Zyxel
    Product
    Usg20w-vpn
    Vendor
    Zyxel
    Product
    Usg20w-vpn Firmware
    Vendor
    Zyxel
    Product
    Usg210
    Vendor
    Zyxel
    Product
    Usg210 Firmware
    Vendor
    Zyxel
    Product
    Usg2200
    Vendor
    Zyxel
    Product
    Usg2200 Firmware
    Vendor
    Zyxel
    Product
    Usg310
    Vendor
    Zyxel
    Product
    Usg310 Firmware
    Vendor
    Zyxel
    Product
    Usg40
    Vendor
    Zyxel
    Product
    Usg40 Firmware
    Vendor
    Zyxel
    Product
    Usg40w
    Vendor
    Zyxel
    Product
    Usg40w Firmware
    Vendor
    Zyxel
    Product
    Usg60
    Vendor
    Zyxel
    Product
    Usg60 Firmware
    Vendor
    Zyxel
    Product
    Usg60w
    Vendor
    Zyxel
    Product
    Usg60w Firmware
    Vendor
    Zyxel
    Product
    Vpn100
    Vendor
    Zyxel
    Product
    Vpn1000
    Vendor
    Zyxel
    Product
    Vpn1000 Firmware
    Vendor
    Zyxel
    Product
    Vpn100 Firmware
    Vendor
    Zyxel
    Product
    Vpn300
    Vendor
    Zyxel
    Product
    Vpn300 Firmware
    Vendor
    Zyxel
    Product
    Vpn50
    Vendor
    Zyxel
    Product
    Vpn50 Firmware
    Vendor
    Zyxel
    Product
    Zywall110
    Vendor
    Zyxel
    Product
    Zywall1100
    Vendor
    Zyxel
    Product
    Zywall1100 Firmware
    Vendor
    Zyxel
    Product
    Zywall110 Firmware
    Vendor
    Zyxel
    Product
    Zywall310
    Vendor
    Zyxel
    Product
    Zywall310 Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High