Zyxel warns of critical OS command injection flaw in routers
ID: de1a8c7f-0991-5a7e-b350-b0466ef1987a
STIX ID: report--de1a8c7f-0991-5a7e-b350-b0466ef1987a
Feed Name: Bleeping Computer
Zyxel released security updates to address a critical unauthenticated OS command injection (CVE-2024-7261, CVSS 9.8) impacting numerous access point and router models that could allow remote command execution via a crafted cookie; vendor advisories list affected models, vulnerable firmware versions, and fixed versions. The advisory also details multiple high‑severity vulnerabilities in APT and USG FLEX firewalls (including an unauthenticated IPSec VPN command injection CVE-2024-42057, CVSS 8.1) and recommends applying provided firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
