zyxel News Articles

Recent news articles refferecing the vendors vulnerabilities.

Zyxel won't patch end-of-life routers against zero-day attacks | Te...

Networking hardware vendor Zyxel on Tuesday said it has no plans to patch affected end-of-life routers against three exploited zero-day vulnerabilities.

Swap EOL Zyxel routers, upgrade Netgear ones! - Help Net Security

There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has finally confirmed.

Zyxel won’t patch newly exploited flaws in end-of-life routers

Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models.

Medical monitoring machines spotted stealing patient data

Infosec in brief The United States Food and Drug Administration has told medical facilities and caregivers that monitor patients using Contec equipment to disconnect the devices from the internet ASAP. The...

Fix Critical Tenda AC8 Router Vulnerability CVE-2024-40891

Learn how to mitigate the critical security vulnerability CVE-2024-40891 in Tenda AC8 routers. Step-by-step guide for security professionals.

Unpatched Zyxel CPE Zero-Day Pummeled by Cyberattackers

VulnCheck initially disclosed the critical command-injection vulnerability (CVE-2024-40891) six months ago, but Zyxel has yet to mention its existence or offer users a patch to mitigate threats.

Hackers exploit critical unpatched flaw in Zyxel CPE devices

Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July.

Zyxel CPE Zero-Day (CVE-2024-40891) Exploited in the Wild

Security researchers newly discovered zero-day command injection vulnerability in Zyxel CPE Series devices, tracked as CVE-2024-40891.

Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024-40891 Vulnerability

Critical zero-day vulnerability CVE-2024-40891 in Zyxel CPE devices is under active attack, affecting 1,500+ devices.

Zyxel Firewalls Exploited In Helldown Ransomware Attacks

Zyxel firewalls are targeted by Helldown ransomware via CVE-2024-11667. CERT-Bund warns of the risks and provides steps to secure devices.

Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342) - Help Net Security

Users of Zyxel NAS devices are urged to implement hotfixes for an easily exploited command injection vulnerability (CVE-2024-6342).

Critical flaw in Zyxel's secure routers allows OS command execution via cookie (CVE-2024-7261) - Help Net Security

CVE-2024-7261 may allow unauthenticated attackers to execute OS commands on many Zyxel access points and security routers.

Critical Zyxel NAS vulnerability targeted by Mirai-like botnet

Hackread reports that outdated Zyxel network-attached storage devices are being subjected to intrusions by a Mirai-like botnet exploiting the critical Python code injection flaw, tracked as CVE-2024-29973.

ロシア関連グループ、最新の影響力行使キャンペーンでバイデン批判しトランプを称賛 | Codebook|Security News

ロシア関連グループが最新の影響力行使キャンペーンでバイデン大統領を批判し、トランプ前大統領を称賛|「Miraiのような」ボットネットによるEOL Zyxel NASデバイスへの攻撃が確認される(CVE-2024-29973)

Recent Zyxel NAS Vulnerability Exploited by Botnet

A Mirai-like botnet has started exploiting a critical-severity vulnerability in discontinued Zyxel NAS products.

Zyxel NAS Devices Under Attack: Mirai-Like Botnet Exploiting CVE-2024-29973

A new vulnerability, CVE-2024-29973, has been discovered in Zyxel NAS devices, exposing them to attacks from a Mirai-like botnet.

Zyxel Releases Emergency Security Update for NAS Devices

Networking solutions vendor Zyxel fixed critical vulnerabilities in end-of-life network-attached storage devices that allow remote code execution. It left two

Zyxel patches critical flaws in EOL NAS devices - Help Net Security

Zyxel has released patches for CVE-2024-29972, CVE-2024-29973, and CVE-2024-29974, which affect two of its EOL NAS devices.

Zyxel issues emergency RCE patch for end-of-life NAS devices

Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-of-life.

Zyxel NAS Devices Vulnerability Let Attackers Execute Code Remotely

Zyxel has released patches addressing critical command injection and remote code execution vulnerabilities in two of its NAS products.

Zyxel Security Vulnerabilities: DoS, Command Injection & More

Zyxel’s recent security advisory spotlights multiple vulnerabilities present in select firewall and access point models. Failure to take immediate action could leave these devices open to severe security risks. Vulnerability Breakdown CVE-2023-6397 (Firewalls): Potential denial-of-service...