Zyxel issued hotfixes for a severe command injection vulnerability traced as CVE-2024-6342, affecting its NAS326 and NAS542 network-attached storage (NAS) devices.
The flaw reported by security researchers Nanyu Zhong and Jinwei Dong from VARAS@IIE, poses significant risks for it allows bad actor to execute arbitrary operating system commands.
By infosecbulletin
/ Saturday , April 12 2025
Recent incidents continue to bring this into focus with active exploitations of known vulnerabilities as investigations by Fortinet have discovered...
Read More
By infosecbulletin
/ Friday , April 11 2025
The Cybersecurity and Infrastructure Security Agency (CISA) has released ten new advisories regarding Industrial Control Systems (ICS) to highlight serious...
Read More
By infosecbulletin
/ Thursday , April 10 2025
Highlights: # Revenue in the Data Center market is projected to reach US$615.59m in 2025. # Network Infrastructure dominates the...
Read More
By infosecbulletin
/ Wednesday , April 9 2025
The U.S. Treasury Department's Office of the Comptroller of the Currency said on Tuesday, opens new tab that emails of...
Read More
By infosecbulletin
/ Wednesday , April 9 2025
Fortinet has fixed several vulnerabilities in its products, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, FortiVoice, FortiWeb, and FortiSwitch. The vulnerabilities include...
Read More
By infosecbulletin
/ Wednesday , April 9 2025
Microsoft's April security update, released on Tuesday, addressed 121 vulnerabilities, marking the largest patch for the year. Despite a high...
Read More
By infosecbulletin
/ Tuesday , April 8 2025
The spoofing vulnerability, CVE-2025-30401, impacts all WhatsApp Desktop versions for Windows before 2.2450.6, posing a risk to users dealing with...
Read More
By infosecbulletin
/ Tuesday , April 8 2025
In its April 2025 security update, Google patched 62 vulnerabilities in Android, including two zero-days used in targeted attacks. Among...
Read More
By infosecbulletin
/ Tuesday , April 1 2025
Israeli cybersecurity firm Check Point has responded to a hacker who claimed to have stolen valuable information from its systems....
Read More
By infosecbulletin
/ Tuesday , April 1 2025
Apple has issued an urgent security advisory about 3 critical zero-day vulnerabilities—CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085—that are being actively exploited in...
Read More
Its concerning because of its widespread use of Zyxel NAS devices in small to medium-sized businesses (SMBs) for data storage and backup functions.
Zyxel has released hotfixes for its NAS even though they are no longer in the support phase, highlighting the seriousness of security vulnerability. This action shows Zyxel’s commitment to customer safety and the importance of continued security awareness for all devices regardless of their support status.
Zyxel recommends that users apply available hotfixes right away, despite no current active exploitation of the vulnerability. Recent incidents, like CVE:2024-29973 show that NAS devices are appealing targets for cybercriminals, highlighting the importance of quick action to prevent breeches.
Zyxel’s response highlights the importance of security updates for users of older technology. To protect sensitive data, it is essential to promptly apply security patches. Users of Zyxel NAA326 and NAS542 devices should quickly implement the hotfixes to defend against potential attacks.