Zyxel warned that CVE-2020-9054 is a critical pre-authentication remote code execution flaw in the weblogin.cgi component of certain NAS and firewall products, caused by missing authentication that enables OS command injection. The company said affected systems include NAS devices running firmware 5.21 and earlier and several UTM, ATP, and VPN firewall releases on ZLD V4.35 Patch 0 through Patch 2, and urged customers to install firmware updates immediately or apply workarounds for unsupported devices. Zyxel later reiterated the risk after noting that BotenaGo malware was targeting devices with known CVEs, advising organizations to patch or isolate internet-exposed systems.
Palo Alto Networks' Unit 42 reported that a public proof of concept for CVE-2020-9054 was quickly weaponized to compromise vulnerable Zyxel NAS devices and install a Mirai variant dubbed Mukashi. Researchers observed exploitation in the wild beginning March 12, 2020, with attackers using a shell script to fetch architecture-specific bot binaries, erase traces, and enroll devices into a botnet that scans TCP port 23, brute-forces default credentials, and supports multiple DDoS commands. Unit 42 said the malware communicated with 45[.]84[.]196[.]75 over TCP ports 34834 and 4864, while also binding locally to TCP port 23448 to prevent multiple infections on the same host.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Zyxel updated patch firmware versions for NAS326, NAS540, and NAS542 and added guidance related to BotenaGo malware. The revision refreshed remediation details for affected NAS customers.
Zyxel updated the advisory in response to research showing BotenaGo malware targeting devices with known CVEs from multiple vendors. The company again urged users to install applicable updates or isolate unsupported devices.
Palo Alto Networks observed exploitation of CVE-2020-9054 in the wild beginning at 19:07 UTC, with attackers downloading a shell script to infected Zyxel NAS devices that fetched and executed Mirai-variant binaries. The campaign used the flaw to install the new Mukashi malware.
Zyxel updated the advisory again to add a NAS firmware update FAQ. The change provided additional guidance to customers applying fixes for CVE-2020-9054.
Zyxel revised the advisory to update standard firmware download links for NAS products and removed hotfixes. This reflected a packaging change in how fixes were provided to customers.
Zyxel updated its advisory to add affected firewall products to the vulnerable product list and corrected the acknowledgment section. The update expanded the scope beyond NAS devices to include UTM, ATP, and VPN firewall lines.
Zyxel initially released a security advisory for CVE-2020-9054, a remote code execution flaw in weblogin.cgi affecting certain NAS products, and urged customers to install firmware updates or apply mitigations. CERT/CC coordinated the disclosure and Brian Krebs was credited with reporting the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zyxel.com
Open sourcecve.mitre.org
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.