<oembed><type>rich</type><version>1.0</version><title>zCat wrote</title><author_name>zCat (npub1zm…5pnd6)</author_name><author_url>https://yabu.me/npub1zm7jduqq2nmxz5wxh4ujtm00g9vxzqa0r82yt7flvm67yje5gfaqa5pnd6</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>CISA Warns of Zyxel Firewall Vulnerability Exploited in Attacks&#xA;&#xA;The US cybersecurity agency CISA on Tuesday warned that a path traversal vulnerability in multiple Zyxel firewall appliances has been exploited in the wild.&#xA;&#xA;The issue, tracked as CVE-2024-11667 (CVSS score of 7.5), is a high-severity flaw affecting the web management interface of Zyxel ATP, USG FLEX, and USG20(W)-VPN series devices.&#xA;&#xA;Successful exploitation of the security defect could allow an attacker to download or upload files using crafted URLs, a NIST advisory reads.&#xA;&#xA;“An attacker may gain unauthorized access to the system, steal credentials, and create backdoor VPN connections by exploiting the vulnerability,” Qualys warned on Tuesday.&#xA;&#xA;See more: https://www.securityweek.com/cisa-warns-of-zyxel-firewall-vulnerability-exploited-in-attacks/&#xA;&#xA;#cybersecurity #zyxel #exploit</html></oembed>