Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Zyxel Patches Critical Vulnerability in NAS Firmware

Networking solutions provider Zyxel has released patches for a critical-severity vulnerability impacting the firmware of multiple network attached storage (NAS) device models.

Networking solutions provider Zyxel has released patches for a critical-severity vulnerability impacting the firmware of multiple network attached storage (NAS) device models.

The security defect, tracked as CVE-2022-34747, carries a CVSS score of 9.8/10 and is publicly documented as a format string vulnerability impacting Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0.

An attacker could exploit the vulnerability by sending specially crafted UDP packets to the affected products. Successful exploitation of the bug could allow an attacker to execute arbitrary code on the impacted device, the company said in an advisory.

“A format string vulnerability was found in a specific binary of Zyxel NAS products that could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet,” the company added.

[ READ: QNAP Warns of New ‘Deadbolt’ Ransomware Attacks Targeting NAS Users ]

Zyxel says its investigationhas identified only three NAS models that are affected and which are within their support lifetime.

The vendor silently patched the vulnerability in mid-August with firmware updates for NAS326, NAS540, and NAS542 device models, but delayed publication of the flaw details until this week.

Zyxel credited security researcher Shaposhnikov Ilya with reporting the vulnerability.

Advertisement. Scroll to continue reading.

Zyxel’s advisory was published only days after QNAP warned of a new wave of Deadbolt ransomware attacks targeting its NAS users.

NAS devices – which are typically used for storing large amounts of data – are often targeted in ransomware attacks and remote code execution bugs in them could easily lead to complete device compromise.

Previously, Zyxel NAD products were targeted by a variant of the Mirai botnet, in attacks that exploited another critical-severity vulnerability leading to remote code execution.

Related: Details Released for Recently Patched Zyxel Firewall Vulns

Related: QNAP Warns of New ‘Deadbolt’ Ransomware Attacks Targeting NAS Users

Related: Zyxel Patches Zero-Day Flaw in Network Storage Products

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Mike Dube has joined cloud security company Aqua Security as CRO.

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...