Hackers are actively exploiting this leading VPN, so patch now

security
(Image credit: Shutterstock / binarydesign)

Cybercriminals are now actively exploiting a major security vulnerability identified in products shipped by networking firm Zyxel, researchers have discovered.

According to Dutch company Eye Control, an admin-level backdoor account hardcoded into the company’s VPN hardware, as well as its firewalls and access point controllers, could grant attackers access to internal networks and provide a platform for further attacks.

“As the user has admin privileges, this is a serious vulnerability,” said Niels Teusink, a senior cybersecurity specialist at Eye Control. “An attacker could completely compromise the confidentiality, integrity and availability of the device.” 

Since the vulnerability came to light, security firm GreyNoise has identified three separate IP addresses scanning the web for devices using the SSH protocol (a vector for infiltrating the affected Zyxel hardware).

Once the attackers identified an SSH device, they attempted to log-in using the compromised backdoor account credentials.

Zyxel VPN security flaw

Researchers estimate that the vulnerability, which is as serious as they come, is present in circa 100,000 Zyxel devices. The affected products are as follows:

  • Advanced Threat Protection (ATP) series
  • Unified Security Gateway (USG) series
  • USG FLEX series
  • VPN series
  • NXC series

If compromised successfully, these devices could allow the attacker to block traffic or fiddle with firewall settings in preparation for a secondary attack.

“They could also intercept traffic or create VPN accounts to gain access to the network behind the device. Combined with a vulnerability like Zerologon, this could be devastating to small and medium businesses,” added Teusink.

Zyxel released a patch for the majority of affected devices last month, with the exception of the NXC series, but the knowledge that attackers are actively seeking to exploit the flaw now adds an additional element of urgency.

As such, all affected organizations are advised to install the relevant updates as soon as possible, to shield against potential attack.

Via Bleeping Computer

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in VPN Privacy & Security
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale