Vulnerabilities

Critical bug in Zyxel firewalls and VPNs exploited

0

Hackers are exploiting a recently patched critical vulnerability in Zyxel firewall and VPN devices for businesses that could allow an unauthenticated remote attacker to execute code.

On successful exploitation of the bug, it is possible for a remote attacker to inject arbitrary commands without authentication, which can enable setting up a reverse shell.

The vulnerability, tracked as CVE-2022-30525 was discovered by Jacob Baines, lead security researcher at Rapid7. The impacted models includes VPN and ATP series, and USG 100(W), 200, 500, 700, and Flex 50(W)/USG20(W)-VPN.

The security experts at the nonprofit Shadowserver Foundation reported seeing exploitation attempts on May 13, and the foundation has urged users to patch immediately.

Over the weekend, Shadowserver Foundation has stated that at least 20,800 Zyxel firewall models on the open web are potentially affected by the vulnerability. The most popular being USG20-VPN (10K IPs) and USG20W-VPN (5.7K IPs). Most of the CVE-2022-30525 affected models are in the EU with France (4.5K) and Italy (4.4K) having the large number.

Rapid7 reported the vulnerability on April 13, and the Taiwanese hardware maker silently released patches on April 28. However, Rapid7 realized the patch was released on May 9 only, and eventually published its blog and Metasploit module alongside the Zyxel notice.

The researchers stated that they are releasing this disclosure early in order to assist defenders in detecting exploitation and to help them decide when to apply this fix in their own environments, according to their own risk tolerances. They added that silent vulnerability patching tends to only help active attackers, and leaves defenders in the dark about the true risk of newly discovered issues.

Zyxel claimed there was a “miscommunication during the disclosure coordination process” and it “always follows the principles of coordinated disclosure”.

Image Credits : Help Net Security

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Italian CERT: Hacktivists hit govt sites

Previous article

Doctor accused of being ransomware developer

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *