Wednesday , April 23 2025
USG FLEX H series

Zyxel released patches 2 vulns in its USG FLEX H series firewalls

Zyxel Networks has issued critical security patches for two high-severity vulnerabilities in its USG FLEX H series firewalls. These flaws could let attackers gain unauthorized access and escalate their privileges on the devices.

On April 22, 2025, a security advisory was released outlining patches for CVE-2025-1731 and CVE-2025-1732, affecting various firmware versions of the company’s security appliances.

ISPAB president “whatsapp” got hacked via phishing link

Imdadul Haque, the president of Internet Service Provider of Bangladesh (ISPAB) said, I automatically got back my WhatsApp account. What...
Read More
ISPAB president “whatsapp” got hacked via phishing link

Zyxel released patches 2 vulns in its USG FLEX H series firewalls

Zyxel Networks has issued critical security patches for two high-severity vulnerabilities in its USG FLEX H series firewalls. These flaws...
Read More
Zyxel released patches 2 vulns in its USG FLEX H series firewalls

South Korea’s largest SK Telecom Hit by Malware: SIM-related info leaked

South Korea's largest mobile operator, SK Telecom, is warning that a malware infection allowed threat actors to access sensitive USIM-related...
Read More
South Korea’s largest SK Telecom Hit by Malware: SIM-related info leaked

ChatGPT Develops Exploit for CVEs Before Public PoCs Share

Security researcher Matt Keeley showed that artificial intelligence can now develop working exploits for critical vulnerabilities before public proof-of-concept (PoC)...
Read More
ChatGPT Develops Exploit for CVEs Before Public PoCs Share

TP-Link Router Vulns Allow to Execute Malicious SQL Commands

Several vulnerabilities have been found in TP-Link routers, exposing users to serious security risks from SQL injection flaws in their...
Read More
TP-Link Router Vulns Allow to Execute Malicious SQL Commands

SSL.comโ€™s domain validation system’s bug found: Hacker exploited

SSL.com has revealed a major security flaw in its domain validation system, which could enable attackers to acquire fake SSL...
Read More
SSL.comโ€™s domain validation system’s bug found: Hacker exploited

Amazon Follows Microsoft’s Lead, Halts Some Data Center Deals

Amazon has paused some data center lease negotiations for its cloud division, particularly in international markets, according to Wells Fargo...
Read More
Amazon Follows Microsoft’s Lead, Halts Some Data Center Deals

Hackers Exploit Zoom’s Remote Control Feature for System Access

ELUSIVE COMET is a threat actor conducting a sophisticated attack campaign that uses Zoom's remote control feature to access victims'...
Read More
Hackers Exploit Zoom’s Remote Control Feature for System Access

Registration open for โ€˜๐”๐€๐ ๐‚๐˜๐๐„๐‘ ๐’๐ˆ๐„๐†๐„ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“โ€™

๐“๐ก๐ž ๐‚๐ฒ๐›๐ž๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐‚๐ฅ๐ฎ๐› of University of Asia Pacific (UAP) is going to arrange โ€˜๐”๐€๐ ๐‚๐˜๐๐„๐‘ ๐’๐ˆ๐„๐†๐„ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“โ€™ ๐‚๐š๐ฉ๐ญ๐ฎ๐ซ๐ž ๐“๐ก๐ž...
Read More
Registration open for โ€˜๐”๐€๐ ๐‚๐˜๐๐„๐‘ ๐’๐ˆ๐„๐†๐„ ๐Ÿ๐ŸŽ๐Ÿ๐Ÿ“โ€™

Samsung phone is saving your passwords in plain text

You copy a password from your manager, thinking it's safe. Meanwhile, your phone is saving it in plain text. Samsung...
Read More
Samsung phone is saving your passwords in plain text

Zyxel USG FLEX H Series Vulnerabilities:

Security researchers found a vulnerability (CVE-2025-1731) in the PostgreSQL commands of USG FLEX H series uOS firmware versions V1.20 to V1.31 due to incorrect permission assignments.

This critical flaw has a CVSS score of 7.8, highlighting its serious security threat. It may allow a low-privileged, authenticated local attacker to access the Linux shell and elevate their privileges to the administrator level.

The advisory explains that โ€ the exploitation path is particularly concerning as it enables attackers to craft malicious scripts or modify system configurations through a stolen token. โ€œ

โ€œHowever, modification of system configurations is only possible if the administrator remains logged in and their token remains valid.โ€

The second vulnerability, CVE-2025-1732, relates to improper privilege management in the recovery function of the same firmware versions.

This vulnerability allows an authenticated local attacker with admin privileges to upload a specially crafted configuration file, potentially escalating their privileges on affected devices.

Security researchers Alessandro Sgreccia from HackerHood and Marco Ivaldi from HN Security discovered the vulnerabilities.

Affected Systems and Patch Released:

Zyxel’s investigation found that only the USG FLEX H series is vulnerable during the current support period. They have released firmware update uOS V1.32 to fix these vulnerabilities.

Security experts advise prompt patching due to the frequent exploitation of privilege escalation vulnerabilities in targeted enterprise attacks.

The USG FLEX H series is Zyxel’s advanced security solution, offering three times the performance in firewall, VPN, and Unified Threat Management compared to earlier models, thanks to its next-generation multi-core hardware.

Users should promptly install the patches and adopt defense-in-depth strategies, such as reducing external management interface exposure and enforcing strong authentication policies.

Check Also

SSL.com

SSL.comโ€™s domain validation system’s bug found: Hacker exploited

SSL.com has revealed a major security flaw in its domain validation system, which could enable …

Leave a Reply

Your email address will not be published. Required fields are marked *