CVE-2024-42057
published 2024-09-03CVE-2024-42057: A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions…
PriorityP185high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.32%
67.6th percentile
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20_vpn_series_firmware | — | — |
| zyxel | usg_flex_50_series_firmware | — | — |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | zld | >= 4.16 < 5.39 | 5.39 |
| zyxel | zld | >= 4.32 < 5.39 | 5.39 |
| zyxel | zld | >= 4.50 < 5.39 | 5.39 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect creation of suspicious local user account 'OKSDW82A' on Zyxel firewall devices, which is a strong indicator of CVE-2024-42057 exploitation by Helldown ransomware actors. ↗
- →Monitor for presence of 'zzz1.conf' configuration file on MIPS-based Zyxel firewall devices as an artifact of post-exploitation activity. ↗
- →Alert on SSL VPN logins from the account 'OKSDW82A' used to establish initial access into victim networks after firewall compromise. ↗
- →Flag IPSec VPN authentication attempts using usernames exceeding 28 characters in User-Based-PSK mode on Zyxel ATP, USG FLEX, USG FLEX 50(W), and USG20(W)-VPN devices running firmware V4.16–V5.38 as potential CVE-2024-42057 exploitation attempts. ↗
- →Hunt for ELF binaries compiled for MIPS architecture uploaded or dropped on Zyxel firewall devices, potentially base64-encoded in transit, as a payload delivery indicator. ↗
- →Detect ransomware file extension patterns matching random 8-character alphanumeric strings (e.g., 'FGqogsxF') appended to encrypted files, paired with a 'Readme.<ext>.txt' ransom note, as Helldown ransomware artifacts. ↗
- ·CVE-2024-42057 is only exploitable when the Zyxel device is configured in User-Based-PSK authentication mode AND a valid user account with a username longer than 28 characters exists on the device. ↗
- ·Affected firmware versions span a wide range: ATP/USG FLEX V4.32–V5.38, USG FLEX 50(W)/USG20(W)-VPN V4.16–V5.38. The fix was released in firmware version 5.39 on September 3, 2024. ↗
- ·Sekoia attributes Helldown's exploitation of Zyxel with only medium confidence; a separate undocumented Zyxel vulnerability may also be involved. ↗
- ·Public exploitation details for CVE-2024-42057 had not been released as of the report date; Helldown is suspected of using private n-day exploits. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vf97-4vg7-22rv: A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4
ghsa_unreviewed·2024-09-03
CVE-2024-42057 [HIGH] CWE-78 GHSA-vf97-4vg7-22rv: A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
VulnCheck
Zyxel zld Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2024·CVSS 8.1
CVE-2024-42057 [HIGH] Zyxel zld Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Zyxel zld Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
Affected: Zyxel zld
Required Action: Apply remedia
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Helldown ransomware exploits Zyxel VPN flaw to breach networks
blogs_bleepingcomputer·2024-11-19
Helldown ransomware exploits Zyxel VPN flaw to breach networks
## Helldown ransomware exploits Zyxel VPN flaw to breach networks
## Bill Toulas
The new 'Helldown' ransomware operation is believed to target vulnerabilities in Zyxel firewalls to breach corporate networks, allowing them to steal data and encrypt devices.
French cybersecurity firm Sekoia is reporting this with medium confidence based on recent observations of Helldown attacks.
Although not among the major players in the ransomware space, Helldown has quickly grown since its launch over the summer, listing numerous victims on its data extortion portal.
## Helldown discovery and overview
Helldown was first documented by Cyfirma on August 9, 2024, and then again by Cyberint on October 13, both briefly describing the new ransomware operation.
The first report of a Linux variant of the
Bleepingcomputer
Zyxel warns of critical OS command injection flaw in routers
blogs_bleepingcomputer·2024-09-03·CVSS 8.1
CVE-2024-7261 [HIGH] Zyxel warns of critical OS command injection flaw in routers
## Zyxel warns of critical OS command injection flaw in routers
## Bill Toulas
The Zyxel access points (APs) impacted by CVE-2024-7261 are the following:
NWA Series : NWA50AX, NWA50AX PRO, NWA55AXE, NWA90AX, NWA90AX PRO, NWA110AX, NWA130BE, NWA210AX, NWA220AX-6E | all versions up to 7.00 are vulnerable, upgrade to 7.00(ABYW.2) and later
NWA1123-AC PRO | all versions up to 6.28 are vulnerable, upgrade to 6.28(ABHD.3) and later
NWA1123ACv3, WAC500, WAC500H | all versions up to 6.70 are vulnerable, upgrade to 6.70(ABVT.5) and later
WAC Series : WAC6103D-I, WAC6502D-S, WAC6503D-S, WAC6552D-S, WAC6553D-E | all versions up to 6.28 are vulnerable, upgrade to 6.28(AAXH.3) and later
WAX Series : WAX300H, WAX510D, WAX610D, WAX620D-6E, WAX630S, WAX640S-6E, WAX650S, WAX655E | all versions up to
2024-09-03
Published
Exploited in the wild