Blog | G5 Cyber Security

Some Zyxel devices can be hacked via DNS requests

Experts at SEC Consult discovered several security issues in various Zyxel devices that allow to hack them via unauthenticated DNS requests. Unauthenticated attacker could exploit the flaw to check whether a domain is present or not via the web login interface. The issue affects devices from the USG, UAG, ATP, VPN and NXC series. Hardcoded credentials can be used to steal the configuration file that includes SSIDs and passwords. The vendor released hotfix and firmware updates at the end of August.”]

Source: https://securityaffairs.co/wordpress/90801/hacking/zyxel-products-flaws.html

Exit mobile version