Blog | G5 Cyber Security

New Firmware for Zyxel WiFi Access Points Removes Embedded Credentials

Zyxel’s NWA, NAP and WAC series are affected by hardcoded credentials embedded in the firmware. Researchers found that multiple WiFi access points had an active File Transfer Protocol (FTP) server that contained the configuration file for the WiFi network. An attacker can use this information to hop to a protected network and reach critical computer systems, the researchers warn. The manufacturer has released new firmware versions that fix the issue, which affects more than two dozen devices from the company’s products.”]

Source: https://www.bitdefender.com/blog/hotforsecurity/new-firmware-zyxel-wifi-access-points-removes-embedded-credentials/

Exit mobile version