critical Known exploitedREV. 01

CVE-2023-27992Zyxel storage devices — commands before the login

A crafted request to these Zyxel network storage devices executes operating system commands before anybody logs in. Firmware below the V5.21 releases on the three affected models carries the flaw.

YOUR NEXT MOVE

Update the Zyxel storage firmware to the V5.21 release for your model, and take these devices off the public internet — the flaw needs no credentials at all.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
84%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2023-06-19
Added to KEV
2023-06-23
Exploit published
Not recorded
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to the device's web interface; no credentials are needed.

Behind the card

3 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-09-24scrty-crds-pipeline/0.1high
exploitation.known_exploited, exploitation.kev_addedcisa.gov2026-09-24scrty-crds-pipeline/0.1high
epssapi.first.org2026-09-24scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-09-24claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2023-27992 · CRDS 0.1 · Issued 2026-09-24