Rewterz
Novel Cross-Platform Malware KTLVdoor Targeting Chinese Trade Company – Active IOCs
September 5, 2024
Rewterz
CVE-2024-6119 – OpenSSL Vulnerability
September 5, 2024

CVE-2024-7261 – Zyxel Vulnerability

Severity

High

Analysis Summary

CVE-2024-7261

Zyxel could allow a remote attacker to execute arbitrary commands on the system, caused by the improper neutralization of special elements in the parameter "host" in the CGI program of some AP and security router versions. By sending a specially crafted cookie, an attacker could exploit this vulnerability to execute OS commands on the system.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2024-7261

Affected Vendors

Zyxel

Affected Products

  • Zyxel NWA1123ACv3 firmware 6.70(ABVT.4)
  • Zyxel WAC500 firmware 6.70(ABVS.4)
  • Zyxel WAX655E firmware 7.00(ACDO.1)
  • Zyxel WBE530 firmware 7.00(ACLE.1)
  • Zyxel USG LITE 60AX firmware V2.00(ACIP.2)

Remediation

Refer to Zyxel Website for patch, upgrade or suggested workaround information.

Zyxel Website