Zyxel has issued a new warning about threat actors exploiting a command injection vulnerability in its recently patched firewall, after security firms noticed a ransomware targeting the flaw for initial compromise.
See also: Microlise confirms ransomware data breach

The bug, tracked as CVE-2024-42057, could allow remote attackers to execute operating system commands on vulnerable devices, without authentication.
Zyxel announced patches for this flaw and six other security flaws on September 3, explaining that only devices configured in User-Based-PSK and on which there is a valid user with a long username exceeding 28 characters.
Zyxel addressed these vulnerabilities with the release of firmware version 5.39 for ATP series devices , USG FLEX and USG FLEX 50(W)/USG20(W)-VPN.
A month later, Zyxel EMEA warned that malicious actors were targeting a vulnerability in a firewall running firmware iterations 4.32 to 5.38 to create fake user accounts and gain access to networks via SSL VPN tunnels.
See also: Blue Yonder suffered a ransomware attack

Last week, cybersecurity firm Sekoia warned of attacks launched by the Helldown, which claimed 31 victims between August and October, including its European subsidiary Zyxel.
At least eight Helldown victims, said , were using Zyxel firewalls as IPSec VPN access points when they were compromised by the vulnerability. The attackers likely targeted CVE-2024-42057 to compromise Zyxel devices running firmware version 5.38.
The cybersecurity firm observed that attackers were creating a fraudulent account named OKSDW82A on a vulnerable device, which was previously observed in a Helldown incident analyzed by Truesec.
Shortly after the report, Zyxel issued an advisory confirming that devices that had not been upgraded to firmware version 5.39 were being targeted by malicious attacks.
See also: Telematics company attacked by “SafePay” Ransomware
Ransomware attacks are one of the most serious threats to cybersecurity today. During these attacks, malicious software encrypts important files and data on a system, demanding a ransom from the owner to restore access. They are often accompanied by threats to delete or publish the data if the required amounts are not paid. Successful attacks can have devastating consequences for businesses, organizations, and users, highlighting the need for increased cybersecurity measures and regular data backup.
Source: securityweek
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
