Zyxel has released security updates and fixes a critical vulnerability affecting many business router models .

The vulnerability allows unauthorized attackers to perform OS command injection. It is tracked as CVE-2024-7261 and has a CVSS v3 rating of 9.8/10 (“critical”). It is an error caused by improper handling of user-supplied data, allowing remote attackers to execute commands on the operating system of the vulnerable system.
See also: Canonical releases updates for AWS vulnerabilities
The Zyxel access points (APs) affected by the CVE-2024-7261 vulnerability are:
- NWA Series: NWA50AX, NWA50AX PRO, NWA55AXE, NWA90AX, NWA90AX PRO, NWA110AX, NWA130BE, NWA210AX, NWA220AX-6E| all versions up to 7.00 are vulnerable, upgrade to 7.00 (ABYW.2) and newer versions
- NWA1123ACv3, WAC500, WAC500H | all versions up to 6.70 are vulnerable, upgrade to 6.70 (ABVT.5) and newer versions
- NWA1123-AC PRO | all versions up to 6.28 are vulnerable, upgrade to 6.28 (ABHD.3) and newer
- WAX Series: WAX300H, WAX510D, WAX610D, WAX620D-6E, WAX630S, WAX640S-6E, WAX650S, WAX655E | all versions up to 7.00 are vulnerable, upgrade to 7.00 (ACHF.2) and newer versions
- WAC Series: WAC6103D-I, WAC6502D-S, WAC6503D-S, WAC6552D-S, WAC6553D-E | all versions up to 6.28 are vulnerable, upgrade to 6.28 (AAXH.3) and newer versions
- WBE Series: WBE530, WBE660S | all versions up to 7.00 are vulnerable, upgrade to 7.00 (ACLE.2) and newer versions
According to Zyxel, the USG LITE 60AX running V2.00 (ACIP.2) is also affected. However, it receives automatic updates from the cloud.
See also: VMware Fusion vulnerability allows malicious code execution
While such vulnerabilities serve as a reminder of the importance of keeping devices and softwaredate, it is also important for users to follow network security best practices. This includes regularly changing default credentials , disabling unnecessary services, and monitoring network traffic for any suspicious activity.
See also: Chrome updates fix high-severity vulnerabilities

What other vulnerabilities did Zyxel fix?;
In addition to the critical vulnerability CVE-2024-7261, Zyxel also fixed some other vulnerabilities in APT and USG FLEX firewalls:
- CVE-2024-6343: Buffer overflow in CGI program could lead to DoS attacks, by a authenticated administrator sending a specially crafted HTTP request.
- CVE-2024-7203: Post-authentication command injection allows an authorized administrator to execute operating system via a crafted CLI command.
- CVE-2024-42057: Command injection in IPSec VPN allows an unauthorized attacker to execute operating system commands.
- CVE-2024-42058: Null pointer dereference could cause DoS via crafted packets sent by an authorized attacker.
- CVE-2024-42059: Post-authentication command injection allows an authorized administrator to execute operating system by uploading a compressed language file via FTP.
- CVE-2024-42060: Post-authentication command injection allows an authorized administrator to execute operating system commands by uploading an internal user agreement file.
- CVE-2024-42061: Reflected XSS in “dynamic_script.cgi” could allow an attacker to trick a user into visiting a malicious URL.
For more details on the affected firewalls , check out Zyxel's report
The vulnerabilities in Zyxel routers and firewalls serve as a reminder of the continued need for vigilance and proactive security measures in today’s digital landscape. Users are urged to apply necessary updates and follow best practices to protect their networks from potential threats . Companies, on the other hand, should prioritize immediate patching and collaborate with security researchers to ensure the security of their customers’ data.
Source: www.bleepingcomputer.com
