{"id":5158,"date":"2022-06-16T09:49:40","date_gmt":"2022-06-16T07:49:40","guid":{"rendered":"https:\/\/allcore.be\/news\/hackers-exploit-critical-bug-in-zyxel-firewalls-and-vpns\/"},"modified":"2023-06-21T11:58:40","modified_gmt":"2023-06-21T09:58:40","slug":"hackers-exploit-critical-bug-in-zyxel-firewalls-and-vpns","status":"publish","type":"post","link":"https:\/\/allcore.be\/en\/news\/hackers-exploit-critical-bug-in-zyxel-firewalls-and-vpns\/","title":{"rendered":"Hackers exploit critical bug in Zyxel firewalls and VPNs"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"5158\" class=\"elementor elementor-5158 elementor-4622\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7a384bd elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7a384bd\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e1ba691\" data-id=\"e1ba691\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3c1e917 elementor-widget elementor-widget-text-editor\" data-id=\"3c1e917\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Hackers have begun exploiting a recently patched critical vulnerability, traced as CVE-2022-30525, that affects Zyxel firewall and enterprise VPN devices.<\/strong><\/p><p>Successful exploitation allows a remote attacker to inject arbitrary commands without authentication, making it possible to set up a reverse shell.<\/p><h3>Getting a shell<\/h3><p>The vulnerability was discovered by<a href=\"https:\/\/twitter.com\/Junior_Baines\/status\/1524750691490619392\" target=\"_blank\" rel=\"nofollow noopener\">Jacob Baines<\/a>, chief security researcher at Rapid7, explaining in a brief technical report how the flaw can be exploited in attacks. A module has been added to the Metasploit penetration testing framework.<\/p><div class=\"cat_quote\" data-darkreader-inline-bgcolor=\"\" data-darkreader-inline-bgimage=\"\" data-darkreader-inline-border-top=\"\" data-darkreader-inline-border-right=\"\" data-darkreader-inline-border-bottom=\"\" data-darkreader-inline-border-left=\"\"><p>&#8220;Commands are executed when the user nobody. This vulnerability is exploited via the \/ztp\/cgi-bin\/handler URI and is the result of passing unsanitized attacker input to the os.system method in lib_wan_settings.py&#8221;- <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/05\/12\/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection\/\" target=\"_blank\" rel=\"nofollow noopener\">Jacob Baines<\/a><\/p><\/div><p>The researcher notes that an attacker could set up a reverse shell using the normal bash <a href=\"https:\/\/gtfobins.github.io\/gtfobins\/bash\/#reverse-shell\" target=\"_blank\" rel=\"nofollow noopener\" data-element-label=\"gtfobin\" data-element-location=\"body\">GTFOBin<\/a>.<\/p><div><figure class=\"image\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1100723\/2022\/Vulnerabilities\/CVE-2022-30525ReverseShell.jpg\" alt=\"Setting up a reverse shell after exploiting CVE-2022-30525 bug in Zyxel firewalls and VPNs\" width=\"619\" height=\"146\"><figcaption><em>source: <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/05\/12\/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection\/\" target=\"_blank\" rel=\"nofollow noopener\">Rapid7<\/a><\/em><\/figcaption><\/figure><\/div><p>Zyxel issued a security advisory for CVE-2022-30525 (9.8 critical severity score) on May 12, announcing that <a href=\"http:\/\/enter%20urlhttps\/\/www.bleepingcomputer.com\/news\/security\/zyxel-fixes-firewall-flaws-that-could-lead-to-hacked-networks\/\" target=\"_blank\" rel=\"nofollow noopener\">a fix had been released<\/a>for the affected models and urging administrators to install the latest updates:<\/p><table class=\"table table-width\" border=\"0\" align=\"center\" data-darkreader-inline-border-bottom=\"\"><tbody class=\"advisory_bg\"><tr><th>Affected model<\/th><th>Affected firmware version<\/th><th>Patch availability<\/th><\/tr><tr><td>USG FLEX 100(W), 200, 500, 700<\/td><td>ZLD V5.00 through ZLD V5.21 Patch 1<\/td><td>ZLD V5.30<\/td><\/tr><tr><td>USG FLEX 50(W) \/ USG20(W)-VPN<\/td><td>ZLD V5.10 through ZLD V5.21 Patch 1<\/td><td>ZLD V5.30<\/td><\/tr><tr><td>ATP series<\/td><td>ZLD V5.10 through ZLD V5.21 Patch 1<\/td><td>ZLD V5.30<\/td><\/tr><tr><td>VPN series<\/td><td>ZLD V4.60 through ZLD V5.21 Patch 1<\/td><td>ZLD V5.30<\/td><\/tr><\/tbody><\/table><p>The severity of the security problem and the damage it could lead to is serious enough for the NSA Cybersecurity Director<a href=\"https:\/\/twitter.com\/NSA_CSDirector\/status\/1525825839262203906\" target=\"_blank\" rel=\"nofollow noopener\">Rob Joyce To warn users of exploitation<\/a> and encourage them to update the firmware version of the device if it is vulnerable.<\/p><p>As of Friday the 13th, security experts from the non-profitt<a href=\"https:\/\/www.shadowserver.org\/\" target=\"_blank\" rel=\"nofollow noopener\">Shadowserver Foundation<\/a> reported seeing attempts at exploitation for CVE-2022-30525.<\/p><p>It is unclear whether these attempts are malicious or simply researchers working to map Zyxel devices that are currently exposed to attacks from advertisers.<\/p><p><a href=\"https:\/\/twitter.com\/Shadowserver\/status\/1525561213115158529\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1100723\/2022\/Vulnerabilities\/CVE-2022-30525Exploitation.jpg\" alt=\"Shadowserver noticed CVE-2022-30525 exploitation attempts\" width=\"596\" height=\"422\"><\/a><\/p><p>Rapid7 scanned the Internet for vulnerable Zyxel products and found more than 15,000 using the Shodan search platform for Internet-connected hardware.<\/p><div><figure class=\"image\"><img decoding=\"async\" class=\"b-lazy b-loaded\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/Security\/shodan(1).png\" alt=\"Zyxel devices vulnerable to CVE-2022-30525\" width=\"986\" height=\"681\"><figcaption><em>source: <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2022\/05\/12\/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection\/\" target=\"_blank\" rel=\"nofollow noopener\">Rapid7<\/a><\/em><\/figcaption><\/figure><\/div><p>Shadowserver performed its own scan and <a href=\"https:\/\/twitter.com\/Shadowserver\/status\/1525771529941921792\" target=\"_blank\" rel=\"nofollow noopener\">found at least 20,800 Zyxel firewall models on the open web<\/a> that may be affected by the vulnerability.<\/p><p>The organization counted the hardware by unique IP addresses and discovered that more than 15,000 of them were <a href=\"https:\/\/www.zyxel.com\/products_services\/Business-Firewall-USG20-VPN-USG20W-VPN\/\" target=\"_blank\" rel=\"nofollow noopener\">USG20-VPN<\/a> and USG20W-VPN, models designed for &#8220;VPN connections between branches and retail chains.&#8221;<\/p><p>The region with the most potentially vulnerable devices is the European Union, with France and Italy having the largest number.<\/p><div><figure class=\"image\"><a href=\"https:\/\/twitter.com\/Shadowserver\/status\/1525771529941921792\" target=\"_blank\" rel=\"nofollow noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"b-lazy b-loaded\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1100723\/2022\/Vulnerabilities\/CVE-2022-30525Geo.jpg\" alt=\"Geographic spread of Zyxel devices potentially vulnerable to CVE-2022-30525\" width=\"1600\" height=\"873\"><\/a><figcaption><em>source: Shadowserver Foundation<\/em><\/figcaption><\/figure><\/div><h3>Detect attempts at abuse<\/h3><p>Given the severity of the vulnerability and the popularity of the devices, security researchers have released code to help administrators detect the security hole and exploitation attempts.<\/p><p>As part of the rescue team of Spanish telecom company Telef\u00f3nica,<a href=\"https:\/\/twitter.com\/z3r00t\" target=\"_blank\" rel=\"nofollow noopener\">z3r00t<\/a>created and published a template for the Nuclei vulnerability scanning solution to detect CVE-2022-30525. <a href=\"https:\/\/gist.github.com\/z3r0-0t\/a3bd4c0015458b018308cca3360a7e24\" target=\"_blank\" rel=\"nofollow noopener\">The Template is available on the author&#8217;s GitHub.<\/a><\/p><p>Another researcher, <a href=\"https:\/\/twitter.com\/__blueNinja\" target=\"_blank\" rel=\"nofollow noopener\">BlueNinja<\/a>, also created a script to detect the unauthenticated remote command injection in Zyxel firewall and VPN products and <a href=\"https:\/\/github.com\/xFFninja\/threat_hunting\/blob\/main\/web\/cve-2022-30525.yaml\" target=\"_blank\" rel=\"nofollow noopener\">published it on GitHub.<\/a><\/p><p> <\/p><p>Source: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-are-exploiting-critical-bug-in-zyxel-firewalls-and-vpns\/\" target=\"_blank\" rel=\"noopener\">Bleepingcomputer.com<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Hackers have begun exploiting a recently patched critical vulnerability, traced as CVE-2022-30525, that affects Zyxel firewall and enterprise VPN devices.<\/p>\n","protected":false},"author":3,"featured_media":5005,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5158","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/comments?post=5158"}],"version-history":[{"count":3,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5158\/revisions"}],"predecessor-version":[{"id":5161,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/posts\/5158\/revisions\/5161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/media\/5005"}],"wp:attachment":[{"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/media?parent=5158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/categories?post=5158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/allcore.be\/en\/wp-json\/wp\/v2\/tags?post=5158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}