ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 529 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2025-3248CVE-2023-28771CVE-2025-23121

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
CVE-2025-23121
Authenticated Domain-User RCE in Veeam Backup & Replication

CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix.

Do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation.

8.822%
  • Veeam Backup & Replication (Backup Server component)
mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations)
CVE-2025-3248
Unauthenticated RCE in Langflow /api/v1/validate/code

Langflow, an open-source visual framework for building LLM and agentic AI applications, contains a missing authentication flaw (CWE-306) in its /api/v1/validate/code endpoint. A remote attacker with network reachability to the endpoint can send crafted HTTP requests without any credentials, causing arbitrary code execution on the server. Successful exploitation yields code execution under the application's privileges, enabling data theft, backdoor installation, and, per CISA, ransomware deployment. Any running Langflow instance is affected; the tool is typically self-hosted by development teams building AI workflows, so real-world exposure depends on whether each instance is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-05-05 with known ransomware use, EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), and a public PoC is available.

Do: Upgrade Langflow to the latest patched release identified in the vendor's advisory; federal agencies must apply mitigations per vendor instructions under BOD 22-01 or discontinue use if mitigations are unavailable. Until patched, restrict network access to the /api/v1/validate/code endpoint via reverse-proxy authentication, firewall rules, or VPN placement, and avoid exposing Langflow directly to the internet. Because ransomware use is confirmed, review access and process-execution logs for signs of prior compromise.

9.8100% KEV ransomware PoC ×2
  • Langflow
moderatetens of thousands of self-hosted deployments, with likely only hundreds to low thousands directly exposed to the internet
Full article421 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

WestJet probes cybersecurity incident affecting app and internal systems  

Europe-wide takedown hits longest-standing dark web drug market

Zoomcar Says Hackers Accessed Data of 8.4 Million Users 

Understanding SCATTERED SPIDER: Tactics, Targets, and Defence Strategies by Daniel Collyer June 4, 2025 

United States Files Civil Forfeiture Complaint Against $225M in Funds Involved in Cryptocurrency Investment Fraud Money Laundering

Krispy Kreme says November data breach impacts over 160,000 people

Cyberattack pushes German napkin company into insolvency 

Infrastructure Laundering: Blending in with the Cloud 

Qilin ransomware top dogs treat their minions to on-call lawyers for fierier negotiations

Malware

Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet  

2025 Blockchain and Cryptocurrency Threat Report: Malware in the Open Source Supply Chain 

Fake Minecraft mods distributed by the Stargazers Ghost Network to steal gamers’ data 

Threat actor Banana Squad exploits GitHub repos in new campaign

AntiDot Malware

Your Mobile App, Their Playground: The Dark side of the Virtualization  

Hacking

GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771 

CISA Warns of Active Exploitation of Linux Kernel Privilege Escalation Vulnerability

 Critical Veeam Backup & Replication CVE-2025-23121  

Iran’s Largest Crypto Exchange Targeted in $90m Hack

The 16-billion-record data breach that no one’s ever heard of 

Qualys TRU Uncovers Chained LPE: SUSE 15 PAM to Full Root via libblockdev/udisks  

Intelligence and Information Warfare          

Predator Still Active, with New Client and Corporate Links Identified 

Washington Post investigating cyberattack on journalists’ email accounts, source says 

Iran Slows Internet to Prevent Cyber Attacks Amid Escalating Regional Conflict

Threat Group Targets Companies in Taiwan

Internet collapses across Iran, say web-monitoring firms  

Viasat identified as victim in Chinese Salt Typhoon cyberespionage, Bloomberg News reports

Iran’s Cyber Army: Missing in Action     

Countering AI Chip Smuggling Has Become a National Security Priority 

Feeling Blue(Noroff): Inside a Sophisticated DPRK Web3 Intrusion

Iran’s government says it shut down internet to protect against cyberattacks 

Cybersecurity

The Impact of Artificial Intelligence on the Cybersecurity Workforce  

The AI Arms Race: Deepfake Generation vs. Detection

Managing Serial-to-Ethernet Exposures in Modern OT Networks

No, the 16 billion credentials leak is not a new data breach

Defending the Internet: how Cloudflare blocked a monumental 7.3 Tbps DDoS attack  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179208/breaking-news/security-affairs-newsletter-round-529-by-pierluigi-paganini-international-edition.html