Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2020-9054

Zyxel | Multiple Network-Attached Storage (NAS) DevicesAdded 2022-03-25Remediation Deadline 2022-04-15

Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References