HomeSecurityBotnet exploits vulnerability in Zyxel NAS devices

Botnet exploits vulnerability in Zyxel NAS devices

Researchers from the Shadowserver Foundation are warning that a botnet, based on Mirai, is exploiting a Zyxel vulnerability tracked as CVE-2024-29973.

Botnet vulnerability in Zyxel NAS

The vulnerability is considered critical (CVSS score 9.8) and affects Zyxel NAS devices that are no longer supported by the company (end-of-life – EoL).

See also: P2PInfect botnet: Targets Redis servers with new ransomware and cryptominer modules

This is a command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0. An unauthorized attacker can exploit this Zyxel vulnerability to execute certain operating system (OS) commands by sending a specially crafted HTTP POST request.

The vulnerability affects NAS326 with firmware version 5.21(AAZF.16)C0 and earlier, and NAS542 with firmware version 5.21(ABAG.13)C0 and earlier.

See also: Muhstik botnet exploits vulnerability in Apache RocketMQ

Researchers at the Shadowserver Foundation have observed attempts to exploit this vulnerability by a Mirai-like botnet. Experts urge the replacement of EoL devices and pointed out that a PoC exploit is publicly available, which means the risk of exploitation is even greater.

Botnet exploits vulnerability in Zyxel NAS devices

These exploit attempts serve as a reminder that end-of-life devices are still vulnerable to . cyberattacksEven if a device is no longer actively supported by the manufacturer, it doesn't mean it can't be exploited by hackers.

See also: Pumpkin Eclipse Botnet destroyed 600,000 routers

To ensure the security of your network, it is important to regularly check the end-of-life status of your devices and upgrade to newer models if possible. If upgrading is not an option, additional security to mitigate potential risks. This could include implementing stricter access controls, using firewalls and intrusion detection systems, and regularly monitoring network activity.

It is also important to immediately apply updates security, such as those released by Zyxel, to fix the vulnerability.

source: securityaffairs.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS