S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-9054 Scanner

Detects 'OS Command Injection' vulnerability in Multiple ZyXEL network-attached storage (NAS) devices affects v. 5.21.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-9054
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NAS326by ZyXEL
V5.21(AAZF.7)C0
NAS520by ZyXEL
V5.21(AASZ.3)C0
NAS540by ZyXEL
V5.21(AATB.4)C0
NAS542by ZyXEL
V5.21(ABAG.4)C0
Updated Aug 21, 2026View on NVD →
Detail

Multiple ZyXEL network-attached storage (NAS) devices are used as storage solutions in many homes, offices, and small businesses. These devices allow users to create a centralized storage space that can be accessed from multiple devices, increasing productivity and ease of use. With ZyXEL NAS devices, users can store and manage files, photos, music, and movies securely and conveniently.

However, a serious vulnerability, CVE-2020-9054, has been detected in ZyXEL NAS devices running firmware version 5.21. This pre-authentication command injection vulnerability can allow remote, unauthenticated attackers to execute arbitrary code on a vulnerable device. Attackers can exploit the vulnerability by sending a specially-crafted HTTP POST or GET request containing certain characters that can cause the username parameter to be improperly sanitized. This vulnerability can be triggered even if an attacker does not have direct connectivity to the vulnerable device.

Affected products include:

  • NAS326 before firmware V5.21(AAZF.7)C0
  • NAS520 before firmware V5.21(AASZ.3)C0
  • NAS540 before firmware V5.21(AATB.4)C0
  • NAS542 before firmware V5.21(ABAG.4)C0

ZyXEL has made firmware updates available for

  • NAS326,
  • NAS520,
  • NAS540, and
  • NAS542 devices.

Affected models that are end-of-support:

  • NSA210,
  • NSA220,
  • NSA220+,
  • NSA221,
  • NSA310,
  • NSA310S,
  • NSA320,
  • NSA320S,
  • NSA325 and
  • NSA325v2

Exploiting CVE-2020-9054 can lead to serious consequences, as it can provide attackers with root privileges on the compromised device. This means that they can execute any command with the highest level of system privileges, which can result in data theft, unauthorized access, and malware deployment. Given the ubiquity of NAS devices in modern networks, this vulnerability presents a significant threat to users' digital assets.

Those who are concerned about the security of their digital assets can benefit from using the pro features of the s4e.io platform. The platform offers users the ability to quickly and easily assess their digital assets' vulnerabilities, providing peace of mind and a more secure online presence. By emphasizing the importance of proactive security measures and using reliable tools, users can reduce the risk of cyberattacks and protect their valuable data.

 

REFERENCES

Solution Advice

To protect against CVE-2020-9054, ZyXEL has released firmware updates for the affected models, including NAS326, NAS520, NAS540, and NAS542. However, users of end-of-support models such as NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325, and NSA325v2 are advised to either upgrade or discontinue use. In addition, users are recommended to take the following precautions:

  • Apply firmware updates as soon as possible.
  • Restrict network access to local users only.
  • Implement firewalls and intrusion prevention systems.
  • Change default login credentials and use strong passwords.
  • Regularly monitor network traffic and logs for unusual activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.