Experts disclose tens of flaws in Zyxel Cloud CNM SecuManager
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-9054 | Pre-Authentication OS Command Injection in Zyxel NAS Devices CVE-2020-9054 is a pre-authentication OS command injection flaw (CWE-78) in multiple Zyxel network-attached storage (NAS) devices. A remote, unauthenticated attacker can send crafted input to the devices' web interface to inject and execute arbitrary OS commands without logging in, resulting in remote code execution on the NAS. Successful exploitation gives the attacker control of the device, which can be used to access, alter or destroy stored data and to pivot into the network the NAS is attached to. Organizations and users running affected Zyxel NAS models are at risk, especially where the management web interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming exploitation in the wild; EPSS assigns a 100% probability of exploitation within 30 days, while no public proof-of-concept is known and any ransomware use is unconfirmed. Do: Apply the firmware updates specified in Zyxel's advisory, per CISA's required action, prioritizing any NAS whose web interface is exposed to the internet. Until patched, restrict the NAS management interface to trusted networks or VPN access and do not expose the admin UI directly to the internet. Because exploitation is confirmed in the wild, check affected devices for indicators of compromise, such as unexpected accounts, scheduled jobs, or outbound connections. | 9.8 | 100% | KEV PoC |
| moderateplausibly tens of thousands of affected devices installed worldwide, with only a low-thousands subset directly internet-exposed |
Full article534 words · extracted from securityaffairs.com · click to collapse

Flaws Riddle Zyxel’s Network Management Software
Experts have found tens of security vulnerabilities in Zyxel Network Management Software, including backdoors and hardcoded SSH keys.
Security researchers Pierre Kim and Alexandre Torres have discovered several vulnerabilities Zyxel Cloud CNM SecuManager software that could expose users to cyber attacks.
The Zyxel Cloud CNM SecuManager is a comprehensive network management software that provides an integrated console to manage security gateways including the ZyWALL USG and VPN Series.
The experts have discovered 16 vulnerabilities, including default credentials to insecure memory storage and backdoors.
Below the full list of issues discovered by the experts:
- Hardcoded SSH server keys
- Backdoors accounts in MySQL
- Hardcoded certificate and backdoor access in Ejabberd
- Open ZODB storage without authentication
- MyZyxel ‘Cloud’ Hardcoded Secret
- Hardcoded Secrets, APIs
- Predefined passwords for admin accounts
- Insecure management over the ‘Cloud’
- xmppCnrSender.py log escape sequence injection
- xmppCnrSender.py no authentication and clear-text communication
- Incorrect HTTP requests cause out of range access in Zope
- XSS on the web interface
- Private SSH key
- Backdoor APIs
- Backdoor management access and RCE
- Pre-auth RCE with chrooted access
“The attack surface is very large and many different stacks are being used it very interesting. Furthermore, some daemons are running as root and are reachable from the WAN. Also, there is no firewall by default.” reads the report published by the researchers.
Giving a close look at the above list we can notice the presence of “Hardcoded SSH server keys” for the main host that could be used by attackers to launch MiTM attacks.
“By default, the appliance uses hardcoded SSH server keys for the main host and for the chroot environments as shown below. This allows an attacker to MITM and decrypt the encrypted traffic.” reads the post published by the experts. “It should be noted the private keys are using wrong permissions and are world-readable (644).”
Experts also discovered the presence of backdoor accounts in MySQL.
“MySQL is pre-configured with several static accounts. It only listens to the loopback interface.”
Experts also reported the use of predefined passwords for admin accounts.
Another bug is related to the use of insecure management over the cloud.
“By default, myzxel.pyc used for communication to the ‘Cloud’ uses some hardcoded variables for communication over HTTPS,” said the experts. “The function get_account_info uses the account_id, the jwt_secret and the jwt_secret_id… The jwt_secret and jwt_secret_id are generated as unique key for each appliance.”
Vulnerable software includes Zyxel CNM SecuManager versions 3.1.0 and 3.1.1 – last updated in November 2018.
One of the researchers, Kim, explained that he did not disclose the vulnerabilities to Zyxel because he suspects that the vendor has intentionally introduced the backdoors into its products.
Zyxel confirmed that is currently investigating the issues disclosed by the experts and pointed out that the CloudCNM SecuManager is a used by a very limited number of customers.
At the time of writing the vendor has yet to publish any advisory on the vulnerabilities reported by the experts.
In February, Zyxel addressed a critical remote code execution vulnerability, tracked as CVE-2020-9054, that impacts several network-attached storage (NAS) devices, the issue is being exploited in the wild.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Zyxel)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/99472/hacking/zyxel-cloud-cnm-secumanager-flaws.html