Zyxel Firewall and VPN Devices Face Critical Security Threats

TL;DR Summary
Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers to achieve code execution. Both the flaws are buffer overflow vulnerabilities and are rated 9.8 out of 10 on the CVSS scoring system. The impacted devices include ATP, USG FLEX, USG FLEX50(W) / USG20(W)-VPN, VPN, and ZyWALL/USG. Security researchers from TRAPA Security and STAR Labs SG have been credited with discovering and reporting the flaws.
- Zyxel Issues Critical Security Patches for Firewall and VPN Products The Hacker News
- Zyxel Firewalls Hacked by Mirai Botnet SecurityWeek
- Zyxel says its firewall and VPN devices have critical security flaws, so patch now TechRadar
- Zyxel warns of critical vulnerabilities in firewall and VPN devices BleepingComputer
- Zyxel firewall and VPN devices affected by critical flaws Security Affairs
Reading Insights
Total Reads
0
Unique Readers
1
Time Saved
1 min
vs 2 min read
Condensed
77%
340 → 79 words
Want the full story? Read the original article
Read on The Hacker News