Over 20 Zyxel Firewalls Impacted by Recent Zero-Day Vulnerability

A recently disclosed zero-day vulnerability in Zyxel network-attached storage (NAS) devices also impacts over twenty of the vendor’s firewalls.


The security flaw, which was issued CVE identifier CVE-2020-9054, can be exploited remotely, without authentication to execute arbitrary code on the affected devices.


Residing in the weblogin.cgi CGI program, the issue is that the username parameter is not properly sanitized. Thus, an attacker could exploit the flaw for command injection by including certain characters in the username.


While weblogin.cgi does not run as root, the vulnerable devices include a setuid utility that the attacker can abuse to run commands with root privileges.


The bug can be exploited by sending a specially-crafted HTTP POST or GET request to a vulnerable device. If the device is not directly exposed to the Internet, but protected by a firewall, exploitation is still possible if the user navigates to a malicious site.


Earlier this week, Zyxel published an advisory on the vulnerability, revealing that it impacted over a dozen NAS devices, including ten that were no longer supported.


On Wednesday, the networking devices vendor updated the advisory to add a total of 23 UTM, ATP, and VPN firewalls to the list of vulnerable products. The flaw, it says, impacts firmware versions ZLD V4.35 Patch 0 through ZLD V4.35 Patch 2.


The list of impacted devices now includes the following firewalls: ATP100, ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200, VPN50, VPN100, VPN300, VPN1000, ZyWALL110, ZyWALL310, and ZyWALL1100.


An exploit for the vulnerability has been available on ..

Support the originator by clicking the read the rest link below.