Nasty Zyxel remote execution bug is being exploited

At the end of last week, Rapid7 disclosed a nasty bug in Zyxel firewalls that could allow for an unauthenticated remote attacker to execute code as the nobody user. The programming issue was not sanitising input, with two fields passed to a CGI handler being fed into system calls.

Read full article on ZDNet

 


Date:

Categorie(s):