Disclosure summary
Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2023-06-23T00:00:00-04:00
MODIFIED 2023-06-23T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00