Get real-time updates on Telegram
CVE-2020-9054: nas326 firmware before 5.21\(aazf.7\)c0 (exclusive); +39 more affected products
CVE-2020-9054. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.99988 (percentile 0.99985), scored 2026-10-06.
Affected technology
nas326 firmware · before 5.21\(aazf.7\)c0 (exclusive)
zyxel
nas520 firmware · before 5.21\(aasz.3\)c0 (exclusive)
zyxel
nas540 firmware · before 5.21\(aatb.4\)c0 (exclusive)
zyxel
nas542 firmware · before 5.21\(abag.4\)c0 (exclusive)
zyxel
atp100 firmware · from 4.35 (inclusive), before 4.35\(abps.3\)c0 (exclusive)
zyxel
atp200 firmware · from 4.35 (inclusive), before 4.35\(abfw.3\)c0 (exclusive)
zyxel
atp500 firmware · from 4.35 (inclusive), before 4.35\(abfu.3\)c0 (exclusive)
zyxel
atp800 firmware · from 4.35 (inclusive), before 4.35\(abiq.3\)c0 (exclusive)
zyxel
usg20-vpn firmware · from 4.35 (inclusive), before 4.35\(abaq.3\)c0 (exclusive)
zyxel
usg20w-vpn firmware · from 4.35 (inclusive), before 4.35\(abar.3\)c0 (exclusive)
zyxel
usg40 firmware · from 4.35 (inclusive), before 4.35\(aala.3\)c0 (exclusive)
zyxel
usg40w firmware · from 4.35 (inclusive), before 4.35\(aalb.3\)c0 (exclusive)
zyxel
usg60 firmware · from 4.35 (inclusive), before 4.35\(aaky.3\)c0 (exclusive)
zyxel
usg60w firmware · from 4.35 (inclusive), before 4.35\(aakz.3\)c0 (exclusive)
zyxel
usg110 firmware · from 4.35 (inclusive), before 4.35\(aaph.3\)c0 (exclusive)
zyxel
usg210 firmware · from 4.35 (inclusive), before 4.35\(aapi.3\)c0 (exclusive)
zyxel
usg310 firmware · from 4.35 (inclusive), before 4.35\(aapj.3\)c0 (exclusive)
zyxel
usg1100 firmware · from 4.35 (inclusive), before 4.35\(aapk.3\)c0 (exclusive)
zyxel
usg1900 firmware · from 4.35 (inclusive), before 4.35\(aapl.3\)c0 (exclusive)
zyxel
usg2200 firmware · from 4.35 (inclusive), before 4.35\(abae.3\)c0 (exclusive)
zyxel
vpn50 firmware · from 4.35 (inclusive), before 4.35\(abhl.3\)c0 (exclusive)
zyxel
vpn100 firmware · from 4.35 (inclusive), before 4.35\(abfv.3\)c0 (exclusive)
zyxel
vpn300 firmware · from 4.35 (inclusive), before 4.35\(abfc.3\)c0 (exclusive)
zyxel
vpn1000 firmware · from 4.35 (inclusive), before 4.35\(abip.3\)c0 (exclusive)
zyxel
zywall110 firmware · from 4.35 (inclusive), before 4.35\(aaaa.3\)c0 (exclusive)
zyxel
zywall310 firmware · from 4.35 (inclusive), before 4.35\(aaab.3\)c0 (exclusive)
zyxel
zywall1100 firmware · from 4.35 (inclusive), before 4.35\(aaac.3\)c0 (exclusive)
zyxel
NAS326 · V5.21(AAZF.7)C0 through V5.21(AAZF.7)C0
ZyXEL
NAS520 · V5.21(AASZ.3)C0 through V5.21(AASZ.3)C0
ZyXEL
NAS540 · V5.21(AATB.4)C0 through V5.21(AATB.4)C0
ZyXEL
NAS542 · V5.21(ABAG.4)C0 through V5.21(ABAG.4)C0
ZyXEL
NSA210 · all
ZyXEL
NSA220 · all
ZyXEL
NSA220+ · all
ZyXEL
NSA221 · all
ZyXEL
NSA310 · V4.75(AALH.2)C0 through V4.75(AALH.2)C0
ZyXEL
NSA320 · all
ZyXEL
NSA320S · V4.75(AANV.2)C0 through V4.75(AANV.2)C0
ZyXEL
NSA325 · V4.81(AAAJ.1)C0 through V4.81(AAAJ.1)C0
ZyXEL
NSA325v2 · V4.81(AALS.1)C0 through V4.81(AALS.1)C0
ZyXEL
Description’s affected range: version 5.21
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
A remote, unauthenticated attacker may execute arbitrary code on a vulnerable device. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-78
- CCR priority
- 64.2 /100 (P2)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.99988 · percentile 0.99985 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 19:02:04.772962+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-9054.html