CVE-2020-9054 | ZyXEL NAS up to 5.20 weblogin.cgi username os command injection
A vulnerability, which was classified as critical, was found in ZyXEL NAS up to 5.20. This affects an unknown part of the file weblogin.cgi. The manipulation of the argument username as part of GET Request leads to os command injection.
This vulnerability is uniquely identified as CVE-2020-9054. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.