Malicious users are exploiting a recently patched critical vulnerability , known as CVE-2022-30525 , which affects Zyxel firewall and enterprise VPN devices
See also: Zyxel fixes critical firewall flaws

Successful exploitation allows a remote attacker to remotely enter arbitrary commands without authentication, which could allow for the setup of a reverse shell.
The vulnerability was discovered by Jacob Baines, lead security researcher at Rapid7, who explains in a short technical report how the flaw in attacks.
The researcher notes that an attacker can create a reverse shell using the regular bash GTFOBin.
Zyxel released a security advisory on May 12 for CVE-2022-30525, which was rated 9.8, announcing that a fix for affected models and urging administrators to install the latest updates.
The severity of the security issue and the damage it could create is serious enough that NSA Cybersecurity Director Rob Joyceis warning users about the exploit and encouraging them to update their device's firmware version if it is vulnerable.
See also: Zyxel fixes critical bug affecting firewall and VPN devices
As of Friday, security experts at the nonprofit Shadowserver Foundation reported seeing attempts to exploit CVE-2022-30525.

It is unclear whether these efforts are malicious or simply researchers working to map Zyxel devices currently exposed to adversary attacks.
Rapid7 scanned the Internet for vulnerable Zyxel products and found more than 15,000 using the Shodan search platform for internet -connected hardware .
Shadowserver did its own scan and found at least 20,800 Zyxel firewall models on the open web that are potentially affected by the vulnerability.
The organization counted the hardware with unique IP addresses and discovered that more than 15,000 of them were USG20-VPN and USG20W-VPN, designed for “VPN connections across all branches and stores in the chain.”
The region with the most vulnerable devices is the European Union, with France and Italy having the largest numbers.
See also: Zyxel: Firewall and VPN systems under attack again
Given the severity of the vulnerability and the popularity of the devices, security researchers have released code that will help administrators identify the security flaw and exploitation attempts.
Another researcher, BlueNinja, also created a script to detect unauthenticated remote command injection in Zyxel firewall and VPN products and published it on GitHub.
