Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Zyxel Patches Critical Vulnerabilities in Networking Devices

Zyxel has released patches for multiple vulnerabilities in its networking devices, including a critical flaw impacting access points and security routers.

Zyxel on Tuesday announced patches for multiple vulnerabilities in its networking devices, including a critical-severity flaw affecting multiple access point (AP) and security router models.

Tracked as CVE-2024-7261 (CVSS score of 9.8), the critical bug is described as an OS command injection issue that could be exploited by remote, unauthenticated attackers via crafted cookies.

The networking device manufacturer has released security updates to address the bug in 28 AP products and one security router model.

The company also announced fixes for seven vulnerabilities in three firewall series devices, namely ATP, USG FLEX, and USG FLEX 50(W)/USG20(W)-VPN products.

Five of the resolved security defects, tracked as CVE-2024-7203, CVE-2024-42057, CVE-2024-42058, CVE-2024-42059, and CVE-2024-42060, are high-severity bugs that could allow attackers to execute arbitrary commands and cause a denial-of-service (DoS) condition.

According to Zyxel, authentication is required for three of the command injection issues, but not for the DoS flaw or the fourth command injection bug (however, this defect is exploitable “only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists”).

Advertisement. Scroll to continue reading.

The company also announced patches for a high-severity buffer overflow vulnerability impacting multiple other networking products. Tracked as CVE-2024-5412, it can be exploited via crafted HTTP requests, without authentication, to cause a DoS condition.

Zyxel has identified at least 50 products affected by this vulnerability. While patches are available for download for four affected models, the owners of the remaining products need to contact their local Zyxel support team to obtain the update file.

The manufacturer makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on Zyxel’s security advisories page.

Related: Recent Zyxel NAS Vulnerability Exploited by Botnet

Related: New BadSpace Backdoor Deployed in Drive-By Attacks

Related: Impacted Vendors Release Advisories for FragAttacks Vulnerabilities

Related: Vendor Quickly Patches Serious Vulnerability in NATO-Approved Firewall

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

David Cass has joined Grayscale Investments as Chief Risk Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.