Previous All Posts Next

Zyxel Backdoor Found: Update Your Device Immediately

Posted: January 5, 2021 to Cybersecurity.

Tags: Data Breach, Malware, Cloud Security

Critical Threat Discovered

A hardcoded, admin-level backdoor vulnerability (CVE-2020-29583) has been found in over 1000,000 Zyxel firewalls, VPN gateways, and access point controllers.  Discovered by Eye Control researchers, these backdoor accounts can allow bad actors to access your information either via the web administration panel or the SSH interface This flaw is so vulnerable, in fact, that it is cited as one of the worst types of vulnerabilities for software or applications to even exist, and it is IMPERATIVE that you update your devices ASAP as it could be easy exploited by an opportunistic hacker or group. This vulnerability was found in several of Zyxel's best selling products, including:
  • Advanced Threat Protection (ATP) series (firewall):
  • Unified Security Gateway (USG) series (hybrid firewall/VPN gateway)
  • USG FLEX series (hybrid firewall/VPN gateway)
  • VPN series (VPN gateway)
  • NXC series (WLAN access point controller)
PATCHES ARE AVAILABLE FOR ALL PRODUCTS EXCEPT THE NXC SERIES, which is expected to be available in April.  So it's time to go update your devices. Seriously. Fix it now!  I'll wait... and when you come back, we can discuss what exactly went awry.

Backdoor Anatomy

You know, it's bad when a company experiences a breach but... It's even worse when they fail to learn from their mistakes. Back in 2016, CVE-2016-10401 was discovered. CVE-2016-10401 was a flaw in their devices contained a secret backdoor mechanism that allowed any user to elevate any account to "root level" simply by using the super-user (SU) password "zyad5001." Shockingly easy, but CVE-2020-29583 is actually worse. CVE-2016-10401 at least required hackers to first gain access to a low-privileged account on a Zyxel device (that they would then have to elevate to root);  CVE-2020-29583, on the other hand, does not require attackers to utilize any special conditions in order to take over... Meaning you don't have to be a skilled hacker to exploit this vulnerability. Additionally, the 2016 vulnerability only impacted personal, at home routers; the 2020 vulnerability has impacted a variety of devices, some of which are made for corporate settings, giving attackers a wider range of targets.

Conclusion

As we have mentioned on numerous occasions, one vital step in any cyber hygiene regimen is to UPDATE YOUR SOFTWARE ASAP.  It's also one of the easiest steps to take.  If you would like to learn more about layering your cyber security to protect your home or business, feel free to download our FREE Remote Security Checklist.  While this guide is a good starting point, if you run a business, this will not fully protect you.  If you have additional questions, feel free to give us a call at 919-422-2607 or you can schedule a free consultation online. And remember... Stay safe out there!

Protect Your Business Today

Petronella Technology Group has provided cybersecurity, compliance, and managed IT services from Raleigh, NC for over 23 years. Contact us today for a free consultation and technology assessment.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now