ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Watch Out! Zyxel Firewalls and VPNs Under Active Cyberattack

criticalExploit / PoCimportance 60CVE-2020-29583

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-29583
Hard-Coded 'zyfwp' Admin Backdoor in Zyxel USG Firewall Firmware 4.60

Zyxel USG-series firewall/VPN gateway firmware version 4.60 ships with an undocumented built-in account named 'zyfwp' whose password is unchangeable and stored in cleartext in the firmware image, making the credentials effectively public once the firmware is examined (use of hard-coded credentials, CWE-522). An unauthenticated attacker who can reach the device's SSH server or web management interface can log in with these embedded credentials and gain full administrator privileges, enabling configuration changes, theft of credentials or logs, and pivoting into the networks the firewall protects; the flaw scores 9.8 (CVSS 3.1) because it is network-exploitable with no privileges or user interaction required. Affected products are the twelve Zyxel USG models listed by CISA (USG20-VPN through USG2200), widely deployed in small/medium-business, branch-office, and ISP/MSP-managed networks. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile), and a public PoC write-up plus news reports of active attacks against Zyxel firewalls and VPNs are available.

Do: Upgrade affected USG devices to a firmware release later than 4.60 per Zyxel's advisory (CISA's required action is to apply vendor updates). Until patched, restrict SSH and web management access to trusted networks and review device logs for logins by the 'zyfwp' account, since its password is public and cannot be changed on vulnerable firmware; check for signs of compromise when upgrading.

9.890% KEV PoC
  • Zyxel USG20-VPN firmware 4.60
  • Zyxel USG20W-VPN firmware 4.60
  • Zyxel USG40 firmware 4.60
  • +9 more
largetens of thousands of internet-exposed Zyxel USG firewalls (order 10^4-10^5 devices; total installed base likely higher)
Full article321 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 25, 2021

Taiwanese networking equipment company Zyxel is warning customers of an ongoing attack targeting a "small subset" of its security products such as firewall and VPN servers.

Attributing the attacks to a "sophisticated threat actor," the firm noted that the attacks single out appliances that have remote management or SSL VPN enabled, namely in the USG/ZyWALL, USG FLEX, ATP, and VPN series running on-premise ZLD firmware, implying that the targeted devices are publicly accessible over the internet.

"The threat actor attempts to access a device through WAN; if successful, they then bypass authentication and establish SSL VPN tunnels with unknown user accounts, such as 'zyxel_slIvpn', 'zyxel_ts', or 'zyxel_vpn_test', to manipulate the device's configuration," Zyxel said in an email message, which was shared on Twitter.

As of writing, it's not immediately known if the attacks are exploiting previously known vulnerabilities in Zyxel devices or if they leverage a zero-day flaw to breach the systems. Also unclear is the scale of the attack and the number of users affected.

To reduce the attack surface, the company is recommending customers to disable HTTP/HTTPS services from the WAN and implement a list of restricted geo-IP to enable remote access only from trusted locations.

Earlier this year, Zyxel patched a critical vulnerability in its firmware to remove a hard-coded user account "zyfwp" (CVE-2020-29583) that could be abused by an attacker to login with administrative privileges and compromise the confidentiality, integrity, and availability of the device.

The development comes as enterprise VPNs and other network devices have become a top target of attackers in a series of campaigns aimed at finding new avenues into corporate networks, giving the threat actors the ability to laterally move across the network and gather sensitive intelligence for espionage and other financially-motivated operations.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/06/watch-out-zyxel-firewalls-and-vpns.html