Close Menu
    Facebook X (Twitter) Instagram
    Tuesday, November 11
    Facebook X (Twitter) Instagram
    SecurNerd
    • Home
    • General News
    • Cyber Attacks
    • Threats
    • Vulnerabilities
    • Cybersecurity
    • Contact Us
    • More
      • About US
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
    SecurNerd
    Home»Vulnerabilities»Zyxel Addresses 15 Security Vulnerabilities Across NAS, Firewall, and AP Devices with Latest Patches
    Vulnerabilities

    Zyxel Addresses 15 Security Vulnerabilities Across NAS, Firewall, and AP Devices with Latest Patches

    securnerdBy securnerdDecember 1, 2023No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Zyxel has taken swift action to rectify 15 security vulnerabilities affecting a range of devices, including network-attached storage (NAS), firewalls, and access points (APs). Among these vulnerabilities, three critical flaws posed significant risks, enabling potential attackers to bypass authentication and execute command injections.

    The specific vulnerabilities are detailed as follows:

    1. CVE-2023-35138 (CVSS score: 9.8) – A critical command injection vulnerability that permits unauthenticated attackers to execute operating system commands through a carefully crafted HTTP POST request.
    2. CVE-2023-4473 (CVSS score: 9.8) – A critical command injection vulnerability within the web server, allowing unauthenticated attackers to execute operating system commands via a manipulated URL directed at a vulnerable device.
    3. CVE-2023-4474 (CVSS score: 9.8) – An imperative improper neutralization of special elements vulnerability enabling unauthenticated attackers to execute operating system commands through a specifically crafted URL.

    Zyxel has also addressed three high-severity flaws (CVE-2023-35137, CVE-2023-37927, and CVE-2023-37928). Exploiting these vulnerabilities could potentially grant attackers access to system information and the ability to execute arbitrary commands. It’s noteworthy that CVE-2023-37927 and CVE-2023-37928 require authentication for successful exploitation.

    The impacted models and versions include:

    • NAS326: Versions V5.21(AAZF.14)C0 and earlier (Patched in V5.21(AAZF.15)C0)
    • NAS542: Versions V5.21(ABAG.11)C0 and earlier (Patched in V5.21(ABAG.12)C0)

    This comprehensive advisory follows closely on the heels of Zyxel’s recent fixes for nine vulnerabilities in specific firewall and access point versions. Some of these could potentially be weaponized to gain unauthorized access to system files and administrator logs, or even trigger a denial-of-service (DoS) condition.

    Given the historical exploitation of Zyxel devices by threat actors, users are strongly urged to promptly apply the latest updates to fortify their systems against potential security threats.

    Found this news interesting? Follow us on Twitter  and Telegram to read more exclusive content we post.

    Post Views: 54
    Featured
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow Hackers Phish for Your Users’ Credentials and Sell Them
    Next Article Qilin Ransomware’s Latest Variant Targets VMware ESXi Servers with Advanced Linux Encryptor
    securnerd
    • Website
    • Facebook
    • X (Twitter)
    • Instagram

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Related Posts

    Python June 23, 2024

    PyQt Mastery: From Beginner to Advanced

    June 23, 2024
    AI June 9, 2024

    Learn AI by yourself! Recommended AI study and learning methods that beginners won’t be discouraged by!

    June 9, 2024
    AI June 7, 2024

    Foundation Models: The Heart of Generative AI

    June 7, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    Join the Community
    Recent Post

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024

    Top 7 Open-Source LLMs for 2024 and Their Uses

    July 18, 2024
    About Us
    About Us

    We're your premier source for the latest in AI, cybersecurity, science, and technology. Dedicated to providing clear, thorough, and accurate information, our team brings you insights into the innovations that shape tomorrow. Let's navigate the future together."

    Latest

    Complete HTML Handwritten Notes

    July 22, 2024

    Complete C++ Handwritten Notes From Basic to Advanced

    July 21, 2024

    Complete Python Ebook From Basic To Advanced

    July 20, 2024
    Popular Post

    Ukraine Enhances Wartime Efforts Through Advanced Cyber Intelligence Strategies

    August 10, 20235 Views

    A Mild, Sweet Fruit With a Fibrous Center

    September 6, 20230 Views

    Top Men’s Fashion Trends From Spring

    September 6, 20230 Views

    Spicy Crispy Chicken Burger Recipe

    September 6, 20230 Views

    Ethos Technologies Data Breach Settlement Offers Compensation of Up to $5,200 for Affected Individuals

    September 23, 20236 Views

    New Sophisticated and Modular ‘Deadglyph’ Malware Unleashed in Government Cyberattacks

    September 24, 20234 Views

    Ukrainian Authorities Detect Russian Hacker Campaign Seeking Evidence of War Crimes

    September 25, 20232 Views

    Debian Project Launches Debian 12.1 “Bookworm” Featuring 89 Bug Remediations and 26 Security Enhancements

    July 24, 202310 Views

    Gadgets That Will Upgrade Your Home

    September 6, 20230 Views

    For Good Results Must Be Make Good Plan

    September 6, 20230 Views
    Facebook X (Twitter) Instagram Pinterest
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.