Novel Cross-Platform Malware KTLVdoor Targeting Chinese Trade Company – Active IOCs
September 5, 2024CVE-2024-6119 – OpenSSL Vulnerability
September 5, 2024Novel Cross-Platform Malware KTLVdoor Targeting Chinese Trade Company – Active IOCs
September 5, 2024CVE-2024-6119 – OpenSSL Vulnerability
September 5, 2024Severity
High
Analysis Summary
CVE-2024-7261
Zyxel could allow a remote attacker to execute arbitrary commands on the system, caused by the improper neutralization of special elements in the parameter "host" in the CGI program of some AP and security router versions. By sending a specially crafted cookie, an attacker could exploit this vulnerability to execute OS commands on the system.
Impact
- Gain Access
Indicators of Compromise
CVE
- CVE-2024-7261
Affected Vendors
Affected Products
- Zyxel NWA1123ACv3 firmware 6.70(ABVT.4)
- Zyxel WAC500 firmware 6.70(ABVS.4)
- Zyxel WAX655E firmware 7.00(ACDO.1)
- Zyxel WBE530 firmware 7.00(ACLE.1)
- Zyxel USG LITE 60AX firmware V2.00(ACIP.2)
Remediation
Refer to Zyxel Website for patch, upgrade or suggested workaround information.