First published: Tue Sep 03 2024(Updated: )
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Zyxel ZLD Firmware | >=4.32<5.39 | |
Any of | ||
Zyxel ATP100 Firmware | ||
Zyxel ATP100W Firmware | ||
Zyxel Zywall ATP200 | ||
Zyxel ATP500 Firmware | ||
Zyxel ATP700 Firmware | ||
Zyxel Zywall ATP800 Firmware | ||
All of | ||
Zyxel ZLD Firmware | >=4.50<5.39 | |
Any of | ||
Zyxel USG Flex 100 firmware | ||
Zyxel USG FLEX 100ax firmware | ||
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50w | ||
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX 700 firmware | ||
All of | ||
Zyxel ZLD Firmware | >=4.16<5.39 | |
Zyxel USG FLEX 50(W) series firmware | ||
All of | ||
Zyxel ZLD Firmware | >=4.16<5.39 | |
Zyxel USG20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42057 is classified as a critical command injection vulnerability in Zyxel's IPSec VPN feature.
To fix CVE-2024-42057, update your Zyxel device firmware to a version higher than V5.39.
CVE-2024-42057 affects Zyxel ATP series, USG FLEX series, USG FLEX 50(W) series, and USG20(W)-VPN series firmware versions from V4.32 to V5.38.
Yes, CVE-2024-42057 can be exploited remotely, which may allow attackers to execute arbitrary commands on the affected devices.
Exploitation of CVE-2024-42057 can lead to unauthorized access and control over the affected Zyxel devices.