Zyxel warns users against new important vulnerabilities in its NAS gadgets

Zyxel warns users against new important vulnerabilities in its NAS gadgets - cve-2023-27992 - Zyxel vulnerability - CVE-2023

Last updated 14 month ago

Security
nas
vulnerability

Zyxel warns users against new important vulnerabilities in its NAS gadgets



Zyxel is a Taiwanese manufacturer higher known for cellular and broadband community merchandise and a few NAS devices for community-based garage access. Two of these NAS merchandise are stricken by six dangerous vulnerabilities, for which the employer already provided a security update.

Zyxel has these days launched a brand new safety advisory for a group of protection vulnerabilities located in the organisation's NAS devices. The six flaws might be abused to skip authentication protocols and inject malicious commands within the NAS OS, Zyxel has warned. Users are recommended to install the already to be had security patches for "most desirable protection" in their community garage setups.

The newly-located vulnerabilities, which consist of 3 vital flaws with very high severity ratings, are described inside the following CVE-tracked announcements: CVE-2023-35137, CVE-2023-35138, CVE-2023-37927, CVE-2023-37928, CVE-2023-4473, CVE-2023-4474. The first flaw (CVE-2023-35137) has a severity rating of seven.Five and relates to an unsuitable authentication within the Zyxel NAS devices that would permit an unauthenticated attacker to achieve system statistics with a particularly crafted URL.

The second flaw (CVE-2023-35138) is a crucial vulnerability (nine.Eight severity score) in the "show zysync server contents" function, Zyxel explains, that could provide hackers with a way to execute "some" OS commands through sending a particular HTTP POST request. The 0.33 flaw (CVE-2023-37927) is a excessive-severity worm (eight.Eight) with flawed neutralization of special elements in the CGI program, which could permit attackers to execute OS instructions by sending a crafted URL.

The fourth flaw (CVE-2023-37928) is a post-authentication command injection vulnerability (8.8) within the WSGI server, that can over again open an OS command execution opportunity thru a malicious URL. The 5th flaw (CVE-2023-4473) is a vital computer virus (nine.Eight) in Zyxel NAS' internet server that could be exploited the equal manner. Finally, the sixth flaw (CVE-2023-4474) is but some other critical trouble (9.8) arising from the incorrect neutralization of unique factors in the WSGI server.

Zyxel stated the work achieved by 3 researchers (Maxim Suslov, Gábor Selján, Drew Balfour) in discovering the safety flaws. The business enterprise performed a "thorough investigation" to identify the supported gadgets tormented by the issues, which encompass the NAS326 and NAS542 community garage models.

The Taiwanese producer failed to provide any possible mitigation measures or workaround to shield the devices in opposition to the new flaws. To keep their information safe from cyber-criminals, customers want to put in the subsequent firmware updates: V5.21(AAZF.15)C0 for NAS326, V5.21(ABAG.12)C0 for NAS542.

  • cve-2023-27992

  • Zyxel vulnerability

  • CVE-2023-20887

  • CVE-2023-28702

  • zyxel command injection cve-2023-28771

  • CVE-2023 1620

  • CVE-2023-1619

  • CVE-2023-20867

Nvidia's next access-level card will be a inexpensive RTX 3050 with 6GB of VRAM

Nvidia's next access-level card will be a inexpensive RTX 3050 with 6GB of VRAM

Rumor mill: These days it is difficult to get excited via a pictures card with just six gigabytes of VRAM, however it seems groups like Nvidia will make one if it makes modern technology models appear like a better deal...

Last updated 14 month ago

Back with a vengeance: SSD expenses to surge in 2024

Back with a vengeance: SSD expenses to surge in 2024

 NAND flash costs are expected to boom by as plenty as 50 percent inside the short time period, to be able to sooner or later bring about greater luxurious stable-country drives. If you are at the fence about a brand ne...

Last updated 13 month ago

Federal judge regulations DoJ can put up Google antitrust well-knownshows on line, ending a one-week media blackout

Federal judge regulations DoJ can put up Google antitrust well-knownshows on line, ending a one-week media blackout

 Despite Alphabet's objections, the decide presiding over the US Justice Department's antitrust lawsuit in opposition to Google dominated that the DoJ can put up trial documents on line. However, the ruling is not with ...

Last updated 16 month ago

Nvidia and AMD are planning Arm-primarily based CPUs for purchaser PCs

Nvidia and AMD are planning Arm-primarily based CPUs for purchaser PCs

Forward-looking: An Arm revolution may be coming to the PC as quickly as 2025. According to a brand new file, Nvidia is making plans to launch CPUs based totally at the structure designed specifically to run Windows, ev...

Last updated 15 month ago

ScummVM helps you to play classic games on structures they had been never designed for

ScummVM helps you to play classic games on structures they had been never designed for

ScummVM is a software which allows you to run positive conventional graphical journey and position-gambling games, provided you have already got their statistics files. The smart element about this: ScummVM simply repla...

Last updated 13 month ago

Microsoft acquisition of Activision Blizzard set to complete after UK regulator gives approval

Microsoft acquisition of Activision Blizzard set to complete after UK regulator gives approval

What just took place? Microsoft has cleared what seems to had been the very last hurdle in its protracted $69 billion acquisition of Activision Blizzard. The UK's Competition and Markets Authority (CMA) has given its po...

Last updated 16 month ago


safirsoft.com© 2023 All rights reserved

HOME | TERMS & CONDITIONS | PRIVACY POLICY | Contact