logo

Zyxel warns of critical OS command injection flaw in routers

ID: de1a8c7f-0991-5a7e-b350-b0466ef1987a

STIX ID: report--de1a8c7f-0991-5a7e-b350-b0466ef1987a

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-09-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Zyxel released security updates to address a critical unauthenticated OS command injection (CVE-2024-7261, CVSS 9.8) impacting numerous access point and router models that could allow remote command execution via a crafted cookie; vendor advisories list affected models, vulnerable firmware versions, and fixed versions. The advisory also details multiple high‑severity vulnerabilities in APT and USG FLEX firewalls (including an unauthenticated IPSec VPN command injection CVE-2024-42057, CVSS 8.1) and recommends applying provided firmware updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.