ZeroHour
Security Affairspublished ()ingested @securityaffairs

Zyxel addressed critical flaw CVE-2023

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27992
Unauthenticated Command Injection in Zyxel NAS326, NAS540, NAS542

Zyxel NAS326, NAS540, and NAS542 network-attached storage devices contain a pre-authentication command injection flaw (CWE-78) that lets an unauthenticated attacker execute operating system commands by sending a crafted HTTP request to the device. Because the flaw is network-facing and requires no credentials or user interaction, a remote attacker gains the ability to run arbitrary OS commands on the device, effectively full compromise. Affected firmware is NAS326 versions prior to V5.21(AAZF.14)C0, NAS540 versions prior to V5.21(AATB.11)C0, and NAS542 versions prior to V5.21(ABAG.11)C0. The flaw scores 9.8 (critical) on CVSS 3.1, carries a very high 83.8% probability of exploitation within 30 days per EPSS, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23. News reporting indicates a Mirai-like botnet is already exploiting the flaw in the wild, so defenders should treat it as an actively exploited, internet-exposable issue and patch immediately.

Do: Upgrade NAS326 to V5.21(AAZF.14)C0, NAS540 to V5.21(AATB.11)C0, and NAS542 to V5.21(ABAG.11)C0 per Zyxel's security advisories. Until patched, keep the NAS web administration interface off the public internet or restrict access with firewall rules. Because a Mirai-like botnet is actively exploiting this flaw, inspect patched and unpatched devices for signs of compromise, such as unfamiliar processes or unexpected outbound traffic; organizations covered by CISA's KEV requirements must apply the vendor updates by the required deadline.

9.884% KEV
  • Zyxel NAS326 firmware all versions prior to V5.21(AAZF.14)C0
  • Zyxel NAS540 firmware all versions prior to V5.21(AATB.11)C0
  • Zyxel NAS542 firmware all versions prior to V5.21(ABAG.11)C0
nichelikely on the order of thousands of internet-exposed devices out of a modest installed base of these three older NAS models (estimate)
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
CVE-2023-33010
+1 in the same advisory: …33009
Buffer Overflow in Zyxel ATP, USG FLEX, VPN and ZyWALL/USG Firewalls Enables RCE

CVE-2023-33010 is a buffer overflow (CWE-120) in the ID processing function of Zyxel's firewall firmware that is triggered when an affected device processes crafted input sent by an unauthenticated attacker. Successful exploitation can cause denial-of-service conditions and, more seriously, allow remote code execution on the firewall itself, giving an attacker a foothold at the network perimeter. The flaw affects multiple Zyxel firewall lines widely used by small and mid-sized organizations, including ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and legacy ZyWALL/USG models. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (added 2023-06-05), indicating it is being exploited in the wild, though no public proof-of-concept is known and ransomware association is unconfirmed. EPSS puts the 30-day exploitation probability at 28.8% (98th percentile), and no CVSS score has been published yet.

Do: Apply the updated firmware for your specific model per Zyxel's security advisory, since the CISA required action is to patch per vendor instructions. Until patched, restrict or disable WAN-side access to the firewall's management/ID processing interfaces and monitor devices for signs of compromise such as unexpected reboots or crashes. Inventory all ATP, USG FLEX (including 50(W)), USG20(W)-VPN, VPN, and ZyWALL/USG units to confirm none remain unpatched.

9.829% KEV
  • Zyxel ATP series firewalls
  • Zyxel USG FLEX firewalls
  • Zyxel USG FLEX 50(W) firewalls
  • +3 more
large≈tens of thousands of internet-exposed devices from a combined installed base likely well over 100,000 across these firewall lines
Full article345 words · extracted from securityaffairs.com · click to collapse

Zyxel released security updates to address a critical vulnerability affecting its network-attached storage (NAS) devices.

Zyxel released security updates to address a critical security flaw, tracked as CVE-2023-27992 (CVSS score: 9.8), affecting its network-attached storage (NAS) devices.

The vulnerability is a pre-authentication command injection issue that impacts the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0. A remote, unauthenticated attacker can exploit the vulnerability to execute some operating system (OS) commands by sending a specially crafted HTTP request.

“Zyxel has released patches addressing a pre-authentication command injection vulnerability in some NAS versions.” reads the advisory published by Zyxel. “The pre-authentication command injection vulnerability in some Zyxel NAS devices could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request,”

The vulnerability was reported by Andrej Zaujec, NCSC-FI, and Maxim Suslov.

In early June, Zyxel published guidance for protecting firewall and VPN devices from the ongoing attacks and exploiting  CVE-2023-28771CVE-2023-33009, and CVE-2023-33010 vulnerabilities.

Threat actors are actively attempting to exploit the command injection vulnerability  CVE-2023-28771 impacting Zyxel firewalls. Their objective is to leverage this vulnerability to deploy and install malware on the affected systems. US CISA added the vulnerability to its Known Exploited Vulnerability to Catalog based on evidence of active exploitation.

In late April, Zyxel addressed the critical vulnerability CVE-2023-28771 (CVSS score 9.8) in its firewall devices. The company promptly advised customers to install the provided patches in order to mitigate the vulnerability.

The vulnerability is being actively exploited to recruit vulnerable devices in a Mirai-like botnet.

The other two issues, tracked as CVE-2023-33009 and CVE-2023-33010, are critical buffer overflow vulnerabilities. A remote, unauthenticated attacker can can trigger the flaws to cause a denial-of-service (DoS) condition and remote code execution on vulnerable devices.

The company states that devices under attack become unresponsive and their Web GUI or SSH management interface are not reachable.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, firewall)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/147653/hacking/zyxel-cve-2023-27992-nas-devices.html