Researchers from the Shadowserver Foundation are warning that a botnet, based on Mirai, is exploiting a Zyxel vulnerability tracked as CVE-2024-29973.

The vulnerability is considered critical (CVSS score 9.8) and affects Zyxel NAS devices that are no longer supported by the company (end-of-life – EoL).
See also: P2PInfect botnet: Targets Redis servers with new ransomware and cryptominer modules
This is a command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0. An unauthorized attacker can exploit this Zyxel vulnerability to execute certain operating system (OS) commands by sending a specially crafted HTTP POST request.
The vulnerability affects NAS326 with firmware version 5.21(AAZF.16)C0 and earlier, and NAS542 with firmware version 5.21(ABAG.13)C0 and earlier.
See also: Muhstik botnet exploits vulnerability in Apache RocketMQ
Researchers at the Shadowserver Foundation have observed attempts to exploit this vulnerability by a Mirai-like botnet. Experts urge the replacement of EoL devices and pointed out that a PoC exploit is publicly available, which means the risk of exploitation is even greater.

These exploit attempts serve as a reminder that end-of-life devices are still vulnerable to . cyberattacksEven if a device is no longer actively supported by the manufacturer, it doesn't mean it can't be exploited by hackers.
See also: Pumpkin Eclipse Botnet destroyed 600,000 routers
To ensure the security of your network, it is important to regularly check the end-of-life status of your devices and upgrade to newer models if possible. If upgrading is not an option, additional security to mitigate potential risks. This could include implementing stricter access controls, using firewalls and intrusion detection systems, and regularly monitoring network activity.
It is also important to immediately apply updates security, such as those released by Zyxel, to fix the vulnerability.
source: securityaffairs.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
