HomeSecurityGafgyt: Exploits a five-year-old flaw in Zyxel EoL

Gafgyt: Exploits a five-year-old flaw in Zyxel EoL

Fortinet has issued a warning about the Gafgyt botnet malware, which is actively attempting to exploit a vulnerability in the Zyxel EoL router. This vulnerability is present in the last phase of the router's lifecycle and leads to thousands of attacks every day.

See also: BitForge: New cryptocurrency wallet zero day flaws allow crypto theft
Gafgyt

Gafgyt targets CVE-2017-18368, a critical (CVSS v3:9.8) command injection vulnerability in the device's remote logging system forwarding function. This vulnerability was patched by Zyxel in 2017.

Zyxel previously warned about the risk from the then-new Gafgyt variant in 2019, urging users to upgrade their outdated firmware to the latest version to protect their devices from attacks. However, Fortinet continues to face an average of 7,100 attacks per day as of early July 2023, with the number of attacks remaining high to this day.

[As of] August 7, 2023, FortiGuard Labs continues to see attack attempts targeting the 2017 vulnerability and has blocked attack attempts on more than a thousand unique IPS devices in the last month,” a new Fortinet alert states.

It is unclear what proportion of the attack attempts resulted in successful infections. However, activity has remained steady since July.

CISA warned of active exploitation of CVE-2017-18368 in this case, adding the vulnerability to its list of known vulnerabilities that are being attacked. The cybersecurity agency is now requiring federal agencies to patch the Zyxel vulnerability by August 28, 2023.

See also: WordPress Ninja Forms: Flaw in plugin allows data theft

EoL Zyxel

In response to the growing exploitation, Zyxel updated its security advisory, notifying customers that CVE-2017-18363 only affects devices running firmware versions 7.3.15.0 v001/3.40(ULM.0)b31 or earlier.

Zyxel P660HN-T1A routers running the latest firmware version released in 2017 to fix the bug, version 3.40(BYF.11), are not affected by these attacks. However, the vendor notes that the device has reached the end of its lifecycle and is no longer supported. Therefore, it would be wise to consider upgrading to a newer model.

Please note that the P660HN-T1A reached end of life several years ago; therefore, we recommend that users replace it with a newer generation product for optimal protection,” Zyxel warns.

Signs of common botnet infections on routers include connection issues, device overheating, unexpected changes to settings, lack of responsiveness, unusual network traffic, opening new ports, and unexpected reboots.

If you suspect a botnet malware breach, it is recommended that you restore factory settings, update your device firmware to the latest version, and change the default administrator user credentials

See also: Ubuntu: 40% of users vulnerable to new privilege elevation flaws

Additionally, it is recommended that you disable remote management and manage devices exclusively from within your network.

Zyxel is one of the most trusted companies offering networking solutions. However, the continuous development and change of technologies requires constant updating and adaptation of products. Therefore, Zyxel encourages its users to regularly upgrade the firmware of their devices and replace old devices with newer models in order to ensure the best possible protection of their data and networks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS