Skip to content
Threat Feed
medium advisory

Remote Code Execution Vulnerability in Zyxel Firewalls

A vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.

The German Federal Office for Information Security (BSI) has released an advisory regarding a security vulnerability affecting Zyxel firewall appliances. The vulnerability allows a remote attacker who has successfully authenticated to the device to execute arbitrary code. The flaw impacts the integrity and security of the affected network infrastructure. Given that firewalls are critical edge components, successful exploitation could grant an attacker full control over the perimeter security appliance, facilitating lateral movement, traffic interception, or persistence within the internal network. Defenders should prioritize auditing administrative access to Zyxel appliances and reviewing management interface logs for unauthorized or suspicious activity by authenticated users.

Impact

Successful exploitation of this vulnerability results in full remote code execution on the affected Zyxel firewall. This allows an attacker to compromise the device, potentially leading to unauthorized network access, data exfiltration, or complete control over the organization's network perimeter. The number of impacted devices or specific firewall models was not disclosed in the initial advisory.

Recommendation

  • Audit all administrative accounts with access to Zyxel firewall management interfaces to ensure credentials have not been compromised.
  • Review management plane logs for unusual command execution patterns or privilege escalation attempts by authenticated users.
  • Apply the security patches provided by Zyxel as soon as they become available for the specific firmware version in use.
  • Restrict access to the firewall management interface to trusted internal IP ranges and disable administrative access from the public internet.

Immediate actions

Restrict firewall management interfaces to authorized management subnets only.

IT Operations 24h