cbcvebase.
CVE-2024-42057
published 2024-09-03

CVE-2024-42057: A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions…

PriorityP185high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.32%
67.6th percentile
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.

Affected

7 ranges
VendorProductVersion rangeFixed in
zyxelatp_series_firmware
zyxelusg20_vpn_series_firmware
zyxelusg_flex_50_series_firmware
zyxelusg_flex_series_firmware
zyxelzld>= 4.16 < 5.395.39
zyxelzld>= 4.32 < 5.395.39
zyxelzld>= 4.50 < 5.395.39

Detection & IOCsextracted from sources · hover to see the quote

filenamezzz1.conf
  • Detect creation of suspicious local user account 'OKSDW82A' on Zyxel firewall devices, which is a strong indicator of CVE-2024-42057 exploitation by Helldown ransomware actors.
  • Monitor for presence of 'zzz1.conf' configuration file on MIPS-based Zyxel firewall devices as an artifact of post-exploitation activity.
  • Alert on SSL VPN logins from the account 'OKSDW82A' used to establish initial access into victim networks after firewall compromise.
  • Flag IPSec VPN authentication attempts using usernames exceeding 28 characters in User-Based-PSK mode on Zyxel ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN devices running firmware V4.16–V5.38 as potential CVE-2024-42057 exploitation attempts.
  • Hunt for ELF binaries compiled for MIPS architecture uploaded or dropped on Zyxel firewall devices, potentially base64-encoded in transit, as a payload delivery indicator.
  • Detect ransomware file extension patterns matching random 8-character alphanumeric strings (e.g., 'FGqogsxF') appended to encrypted files, paired with a 'Readme.<ext>.txt' ransom note, as Helldown ransomware artifacts.
  • ·CVE-2024-42057 is only exploitable when the Zyxel device is configured in User-Based-PSK authentication mode AND a valid user account with a username longer than 28 characters exists on the device.
  • ·Affected firmware versions span a wide range: ATP/USG FLEX V4.32–V5.38, USG FLEX 50(W)/USG20(W)-VPN V4.16–V5.38. The fix was released in firmware version 5.39 on September 3, 2024.
  • ·Sekoia attributes Helldown's exploitation of Zyxel with only medium confidence; a separate undocumented Zyxel vulnerability may also be involved.
  • ·Public exploitation details for CVE-2024-42057 had not been released as of the report date; Helldown is suspected of using private n-day exploits.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.