Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs
July 19, 2023Rewterz Threat Advisory – Multiple Cisco Small Business SPA500 Series IP Phones Vulnerabilities
July 20, 2023Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs
July 19, 2023Rewterz Threat Advisory – Multiple Cisco Small Business SPA500 Series IP Phones Vulnerabilities
July 20, 2023Severity
High
Analysis Summary
CVE-2023-33012 CVSS:8.8
Multiple Zyxel firewalls and WLAN controllers could allow a remote attacker to execute arbitrary commands on the system. By using a crafted GRE configuration, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-33011 CVSS:8.8
Multiple Zyxel firewalls and WLAN controllers could allow a remote attacker to execute arbitrary commands on the system. By using a crafted PPPoE configuration, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34138 CVSS:8
Zyxel firewalls and controllers could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by an OS command injection vulnerability in the hotspot management feature. By tricking an authorized administrator to add their IP address to the list of trusted RADIUS clients, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34139 CVSS:8.8
Zyxel firewalls could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by an OS command injection vulnerability in the Free Time WiFi hotspot feature. An attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2023-34140 CVSS:6.5
Zyxel firewalls and controllers are vulnerable to a denial of service, caused by a buffer overflow. By sending a specially crafted request to the CAPWAP daemon, a remote attacker within the local network could exploit this vulnerability to cause a denial of service.
CVE-2023-34141 CVSS:8
Zyxel firewalls and controllers could allow a remote attacker within the local network to execute arbitrary commands on the system, caused by a command injection vulnerability. By tricking an authorized administrator to add their IP address to the managed AP list, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
Impact
- Command Execution
- Denial of Service
Indicators Of Compromise
CVE
- CVE-2023-33012
- CVE-2023-33011
- CVE-2023-34138
- CVE-2023-34139
- CVE-2023-34140
- CVE-2023-34141
Affected Vendors
Zyxel
Affected Products
- Zyxel ATP series firmware 5.10
- Zyxel ATP series firmware 5.36 Patch 2
- Zyxel USG FLEX series firmware 5.00
- Zyxel USG FLEX series firmware 5.36 Patch 2
- Zyxel USG FLEX 50(W) / USG20(W)-VPN series firmware 5.10
- Zyxel USG FLEX 50(W) / USG20(W)-VPN series firmware 5.36 Patch 2
- Zyxel VPN series firmware 5.00
- Zyxel VPN series firmware 5.36 Patch 2
- Zyxel ATP ZLD 5.31
- Zyxel USG FLEX ZLD 5.31
- Zyxel USG FLEX 50(W) / USG20(W)-VPN ZLD 5.00
- Zyxel VPN ZLD 5.00
Remediation
Refer to the Zyxel Web site for patch, upgrade or suggested workaround information.