zyxel News Articles

Recent news articles refferecing the vendors vulnerabilities.

Zyxel won’t patch newly exploited flaws in end-of-life routers

Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models.

17 hours ago

Medical monitoring machines spotted stealing patient data

Infosec in brief The United States Food and Drug Administration has told medical facilities and caregivers that monitor patients using Contec equipment to disconnect the devices from the internet ASAP. The...

3 days ago

Fix Critical Tenda AC8 Router Vulnerability CVE-2024-40891

Learn how to mitigate the critical security vulnerability CVE-2024-40891 in Tenda AC8 routers. Step-by-step guide for security professionals.

5 days ago

Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers

VulnCheck initially disclosed the critical command-injection vulnerability (CVE-2024-40891) six months ago, but Zyxel has yet to mention its existence or offer users a patch to mitigate threats.

1 week ago

Hackers exploit critical unpatched flaw in Zyxel CPE devices

Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July.

1 week ago

Zyxel CPE Zero-Day (CVE-2024-40891) Exploited in the Wild

Security researchers newly discovered zero-day command injection vulnerability in Zyxel CPE Series devices, tracked as CVE-2024-40891.

1 week ago

Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability

Critical zero-day vulnerability CVE-2024-40891 in Zyxel CPE devices is under active attack, affecting 1,500+ devices.

1 week ago

Zyxel Firewalls Exploited In Helldown Ransomware Attacks

Zyxel firewalls are targeted by Helldown ransomware via CVE-2024-11667. CERT-Bund warns of the risks and provides steps to secure devices.

2 months ago

Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342) - Help Net Security

Users of Zyxel NAS devices are urged to implement hotfixes for an easily exploited command injection vulnerability (CVE-2024-6342).

5 months ago

Critical flaw in Zyxel's secure routers allows OS command execution via cookie (CVE-2024-7261) - Help Net Security

CVE-2024-7261 may allow unauthenticated attackers to execute OS commands on many Zyxel access points and security routers.

5 months ago

Critical Zyxel NAS vulnerability targeted by Mirai-like botnet

Hackread reports that outdated Zyxel network-attached storage devices are being subjected to intrusions by a Mirai-like botnet exploiting the critical Python code injection flaw, tracked as CVE-2024-29973.

7 months ago

ロシア関連グループ、最新の影響力行使キャンペーンでバイデン批判しトランプを称賛 | Codebook|Security News

ロシア関連グループが最新の影響力行使キャンペーンでバイデン大統領を批判し、トランプ前大統領を称賛|「Miraiのような」ボットネットによるEOL Zyxel NASデバイスへの攻撃が確認される(CVE-2024-29973)

7 months ago

Recent Zyxel NAS Vulnerability Exploited by Botnet

A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products.

7 months ago

Zyxel NAS Devices Under Attack: Mirai-Like Botnet Exploiting CVE-2024-29973

A new vulnerability, CVE-2024-29973, has been discovered in Zyxel NAS devices, exposing them to attacks from a Mirai-like botnet.

7 months ago

Zyxel Releases Emergency Security Update for NAS Devices

Networking solutions vendor Zyxel fixed critical vulnerabilities in end-of-life network-attached storage devices that allow remote code execution. It left two

8 months ago

Zyxel patches critical flaws in EOL NAS devices - Help Net Security

Zyxel has released patches for CVE-2024-29972, CVE-2024-29973, and CVE-2024-29974, which affect two of its EOL NAS devices.

8 months ago

Zyxel issues emergency RCE patch for end-of-life NAS devices

Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-of-life.

8 months ago

Zyxel NAS Devices Vulnerability Let Attackers Execute Code Remotely

Zyxel has released patches addressing critical command injection and remote code execution vulnerabilities in two of its NAS products.

8 months ago

Zyxel Security Vulnerabilities: DoS, Command Injection & More

Zyxel’s recent security advisory spotlights multiple vulnerabilities present in select firewall and access point models. Failure to take immediate action could leave these devices open to severe security risks. Vulnerability Breakdown CVE-2023-6397 (Firewalls): Potential denial-of-service...

1 year ago