← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-13364

A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:3.9
Impact Score:2.6
EPSS Probability:1.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
zyxel nas326_firmware all
zyxel nas326 all
zyxel nas520_firmware all
zyxel nas520 all
zyxel nas540_firmware all
zyxel nas540 all
zyxel nas542_firmware all
zyxel nas542 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.151%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-05-21T00:00:00
Published2020-08-06T16:54:43
Last Updated2024-08-04T12:18:18

LINK COPIED TO CLIPBOARD