Zyxel warns users against new important vulnerabilities in its NAS gadgets

Zyxel warns users against new important vulnerabilities in its NAS gadgets - cve-2023-27992 - Zyxel vulnerability - CVE-2023

Last updated 11 month ago

Security
nas
vulnerability

Zyxel warns users against new important vulnerabilities in its NAS gadgets



Zyxel is a Taiwanese manufacturer higher known for cellular and broadband community merchandise and a few NAS devices for community-based garage access. Two of these NAS merchandise are stricken by six dangerous vulnerabilities, for which the employer already provided a security update.

Zyxel has these days launched a brand new safety advisory for a group of protection vulnerabilities located in the organisation's NAS devices. The six flaws might be abused to skip authentication protocols and inject malicious commands within the NAS OS, Zyxel has warned. Users are recommended to install the already to be had security patches for "most desirable protection" in their community garage setups.

The newly-located vulnerabilities, which consist of 3 vital flaws with very high severity ratings, are described inside the following CVE-tracked announcements: CVE-2023-35137, CVE-2023-35138, CVE-2023-37927, CVE-2023-37928, CVE-2023-4473, CVE-2023-4474. The first flaw (CVE-2023-35137) has a severity rating of seven.Five and relates to an unsuitable authentication within the Zyxel NAS devices that would permit an unauthenticated attacker to achieve system statistics with a particularly crafted URL.

The second flaw (CVE-2023-35138) is a crucial vulnerability (nine.Eight severity score) in the "show zysync server contents" function, Zyxel explains, that could provide hackers with a way to execute "some" OS commands through sending a particular HTTP POST request. The 0.33 flaw (CVE-2023-37927) is a excessive-severity worm (eight.Eight) with flawed neutralization of special elements in the CGI program, which could permit attackers to execute OS instructions by sending a crafted URL.

The fourth flaw (CVE-2023-37928) is a post-authentication command injection vulnerability (8.8) within the WSGI server, that can over again open an OS command execution opportunity thru a malicious URL. The 5th flaw (CVE-2023-4473) is a vital computer virus (nine.Eight) in Zyxel NAS' internet server that could be exploited the equal manner. Finally, the sixth flaw (CVE-2023-4474) is but some other critical trouble (9.8) arising from the incorrect neutralization of unique factors in the WSGI server.

Zyxel stated the work achieved by 3 researchers (Maxim Suslov, Gábor Selján, Drew Balfour) in discovering the safety flaws. The business enterprise performed a "thorough investigation" to identify the supported gadgets tormented by the issues, which encompass the NAS326 and NAS542 community garage models.

The Taiwanese producer failed to provide any possible mitigation measures or workaround to shield the devices in opposition to the new flaws. To keep their information safe from cyber-criminals, customers want to put in the subsequent firmware updates: V5.21(AAZF.15)C0 for NAS326, V5.21(ABAG.12)C0 for NAS542.

  • cve-2023-27992

  • Zyxel vulnerability

  • CVE-2023-20887

  • CVE-2023-28702

  • zyxel command injection cve-2023-28771

  • CVE-2023 1620

  • CVE-2023-1619

  • CVE-2023-20867

Stadia controllers can be converted to prevalent Bluetooth gadgets for one greater yr

Stadia controllers can be converted to prevalent Bluetooth gadgets for one greater yr

 Google designed Stadia as a competitor to current on-line gaming services supplied by way of Sony, Microsoft, and Nvidia. The search giant close down its cloud-gaming brainchild after simply more than one years, and th...

Last updated 11 month ago

Qualcomm lives to combat some other day

Qualcomm lives to combat some other day

About a month ago, Qualcomm placed out a barebones press launch – just three sentences – announcing that that they had reached an settlement to keep to selling modems to Apple. This hits pause at the doom narrative walk...

Last updated 13 month ago

Vivaldi 6.5 provides classes panel, synced open tabs, complete records sync

Vivaldi 6.5 provides classes panel, synced open tabs, complete records sync

Vivaldi is a quick, extremely customizable browser that prioritizes your privacy (not our very own income). An Internet browser that adapts to you, no longer the alternative manner round. Vivaldi browser comes packed wi...

Last updated 11 month ago

Apple analyst says iPhone 15 Pro overheating problems because of thermal layout, not the A17 Pro SoC

Apple analyst says iPhone 15 Pro overheating problems because of thermal layout, not the A17 Pro SoC

A warm potato: The new iPhone 15 Pro and Pro Max arrived closing week with lots of tremendous critiques, however plainly Apple's trendy handsets are not with out their problems. There had been several reviews of the dev...

Last updated 14 month ago

The Best SSDs and Fast PC Storage - Holidays 2023

The Best SSDs and Fast PC Storage - Holidays 2023

Fast garage has turn out to be a commodity, and it is anticipated to emerge as even bigger and quicker within the years in advance. For new builds, NVMe drives have emerge as the norm, providing expenses corresponding t...

Last updated 12 month ago

Google lately mitigated the most important DDoS assault ever, peaking at 398 million requests per second

Google lately mitigated the most important DDoS assault ever, peaking at 398 million requests per second

 Google recently helped mitigate the largest allotted denial of provider (DDoS) attack ever recorded, and was it ever a doozy. The series of attacks came about lower back in August and applied a novel HPPT/2 "Rapid...

Last updated 13 month ago


safirsoft.com© 2023 All rights reserved

HOME | TERMS & CONDITIONS | PRIVACY POLICY | Contact