CYBER CODE RED

Get real-time updates on Telegram

P2Verified

CVE-2020-9054: nas326 firmware before 5.21\(aazf.7\)c0 (exclusive); +39 more affected products

CVE-2020-9054. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.99988 (percentile 0.99985), scored 2026-10-06.

Affected technology

nas326 firmware · before 5.21\(aazf.7\)c0 (exclusive)
zyxel

nas520 firmware · before 5.21\(aasz.3\)c0 (exclusive)
zyxel

nas540 firmware · before 5.21\(aatb.4\)c0 (exclusive)
zyxel

nas542 firmware · before 5.21\(abag.4\)c0 (exclusive)
zyxel

atp100 firmware · from 4.35 (inclusive), before 4.35\(abps.3\)c0 (exclusive)
zyxel

atp200 firmware · from 4.35 (inclusive), before 4.35\(abfw.3\)c0 (exclusive)
zyxel

atp500 firmware · from 4.35 (inclusive), before 4.35\(abfu.3\)c0 (exclusive)
zyxel

atp800 firmware · from 4.35 (inclusive), before 4.35\(abiq.3\)c0 (exclusive)
zyxel

usg20-vpn firmware · from 4.35 (inclusive), before 4.35\(abaq.3\)c0 (exclusive)
zyxel

usg20w-vpn firmware · from 4.35 (inclusive), before 4.35\(abar.3\)c0 (exclusive)
zyxel

usg40 firmware · from 4.35 (inclusive), before 4.35\(aala.3\)c0 (exclusive)
zyxel

usg40w firmware · from 4.35 (inclusive), before 4.35\(aalb.3\)c0 (exclusive)
zyxel

usg60 firmware · from 4.35 (inclusive), before 4.35\(aaky.3\)c0 (exclusive)
zyxel

usg60w firmware · from 4.35 (inclusive), before 4.35\(aakz.3\)c0 (exclusive)
zyxel

usg110 firmware · from 4.35 (inclusive), before 4.35\(aaph.3\)c0 (exclusive)
zyxel

usg210 firmware · from 4.35 (inclusive), before 4.35\(aapi.3\)c0 (exclusive)
zyxel

usg310 firmware · from 4.35 (inclusive), before 4.35\(aapj.3\)c0 (exclusive)
zyxel

usg1100 firmware · from 4.35 (inclusive), before 4.35\(aapk.3\)c0 (exclusive)
zyxel

usg1900 firmware · from 4.35 (inclusive), before 4.35\(aapl.3\)c0 (exclusive)
zyxel

usg2200 firmware · from 4.35 (inclusive), before 4.35\(abae.3\)c0 (exclusive)
zyxel

vpn50 firmware · from 4.35 (inclusive), before 4.35\(abhl.3\)c0 (exclusive)
zyxel

vpn100 firmware · from 4.35 (inclusive), before 4.35\(abfv.3\)c0 (exclusive)
zyxel

vpn300 firmware · from 4.35 (inclusive), before 4.35\(abfc.3\)c0 (exclusive)
zyxel

vpn1000 firmware · from 4.35 (inclusive), before 4.35\(abip.3\)c0 (exclusive)
zyxel

zywall110 firmware · from 4.35 (inclusive), before 4.35\(aaaa.3\)c0 (exclusive)
zyxel

zywall310 firmware · from 4.35 (inclusive), before 4.35\(aaab.3\)c0 (exclusive)
zyxel

zywall1100 firmware · from 4.35 (inclusive), before 4.35\(aaac.3\)c0 (exclusive)
zyxel

NAS326 · V5.21(AAZF.7)C0 through V5.21(AAZF.7)C0
ZyXEL

NAS520 · V5.21(AASZ.3)C0 through V5.21(AASZ.3)C0
ZyXEL

NAS540 · V5.21(AATB.4)C0 through V5.21(AATB.4)C0
ZyXEL

NAS542 · V5.21(ABAG.4)C0 through V5.21(ABAG.4)C0
ZyXEL

NSA210 · all
ZyXEL

NSA220 · all
ZyXEL

NSA220+ · all
ZyXEL

NSA221 · all
ZyXEL

NSA310 · V4.75(AALH.2)C0 through V4.75(AALH.2)C0
ZyXEL

NSA320 · all
ZyXEL

NSA320S · V4.75(AANV.2)C0 through V4.75(AANV.2)C0
ZyXEL

NSA325 · V4.81(AAAJ.1)C0 through V4.81(AAAJ.1)C0
ZyXEL

NSA325v2 · V4.81(AALS.1)C0 through V4.81(AALS.1)C0
ZyXEL

Description’s affected range: version 5.21

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

A remote, unauthenticated attacker may execute arbitrary code on a vulnerable device. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-78
CCR priority
64.2 /100 (P2)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.99988 · percentile 0.99985 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-9054.html