zyxel News Articles
Recent news articles refferecing the vendors vulnerabilities.
Zyxel won't patch end-of-life routers against zero-day attacks | Te...
Networking hardware vendor Zyxel on Tuesday said it has no plans to patch affected end-of-life routers against three exploited zero-day vulnerabilities.
Swap EOL Zyxel routers, upgrade Netgear ones! - Help Net Security
There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has finally confirmed.
Zyxel won’t patch newly exploited flaws in end-of-life routers
Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models.
Medical monitoring machines spotted stealing patient data
Infosec in brief The United States Food and Drug Administration has told medical facilities and caregivers that monitor patients using Contec equipment to disconnect the devices from the internet ASAP. The...

Fix Critical Tenda AC8 Router Vulnerability CVE-2024-40891
Learn how to mitigate the critical security vulnerability CVE-2024-40891 in Tenda AC8 routers. Step-by-step guide for security professionals.
Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers
VulnCheck initially disclosed the critical command-injection vulnerability (CVE-2024-40891) six months ago, but Zyxel has yet to mention its existence or offer users a patch to mitigate threats.
Hackers exploit critical unpatched flaw in Zyxel CPE devices
Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July.

Zyxel CPE Zero-Day (CVE-2024-40891) Exploited in the Wild
Security researchers newly discovered zero-day command injection vulnerability in Zyxel CPE Series devices, tracked as CVE-2024-40891.

Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability
Critical zero-day vulnerability CVE-2024-40891 in Zyxel CPE devices is under active attack, affecting 1,500+ devices.

Zyxel Firewalls Exploited In Helldown Ransomware Attacks
Zyxel firewalls are targeted by Helldown ransomware via CVE-2024-11667. CERT-Bund warns of the risks and provides steps to secure devices.
Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342) - Help Net Security
Users of Zyxel NAS devices are urged to implement hotfixes for an easily exploited command injection vulnerability (CVE-2024-6342).
Critical flaw in Zyxel's secure routers allows OS command execution via cookie (CVE-2024-7261) - Help Net Security
CVE-2024-7261 may allow unauthenticated attackers to execute OS commands on many Zyxel access points and security routers.
Critical Zyxel NAS vulnerability targeted by Mirai-like botnet
Hackread reports that outdated Zyxel network-attached storage devices are being subjected to intrusions by a Mirai-like botnet exploiting the critical Python code injection flaw, tracked as CVE-2024-29973.

ロシア関連グループ、最新の影響力行使キャンペーンでバイデン批判しトランプを称賛 | Codebook|Security News
ロシア関連グループが最新の影響力行使キャンペーンでバイデン大統領を批判し、トランプ前大統領を称賛|「Miraiのような」ボットネットによるEOL Zyxel NASデバイスへの攻撃が確認される(CVE-2024-29973)
Recent Zyxel NAS Vulnerability Exploited by Botnet
A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products.

Zyxel NAS Devices Under Attack: Mirai-Like Botnet Exploiting CVE-2024-29973
A new vulnerability, CVE-2024-29973, has been discovered in Zyxel NAS devices, exposing them to attacks from a Mirai-like botnet.
Zyxel Releases Emergency Security Update for NAS Devices
Networking solutions vendor Zyxel fixed critical vulnerabilities in end-of-life network-attached storage devices that allow remote code execution. It left two
Zyxel patches critical flaws in EOL NAS devices - Help Net Security
Zyxel has released patches for CVE-2024-29972, CVE-2024-29973, and CVE-2024-29974, which affect two of its EOL NAS devices.
Zyxel issues emergency RCE patch for end-of-life NAS devices
Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-of-life.
Zyxel NAS Devices Vulnerability Let Attackers Execute Code Remotely
Zyxel has released patches addressing critical command injection and remote code execution vulnerabilities in two of its NAS products.

Zyxel Security Vulnerabilities: DoS, Command Injection & More
Zyxel’s recent security advisory spotlights multiple vulnerabilities present in select firewall and access point models. Failure to take immediate action could leave these devices open to severe security risks. Vulnerability Breakdown CVE-2023-6397 (Firewalls): Potential denial-of-service...