Новости компьютерной безопасности:

  Latest News

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

С сайта: Vulnerability(cybersecuritynews.com)

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

Author: Guru Baran

A critical vulnerability in Zyxel’s ATP and USG series firewalls that allows attackers to bypass authorization controls and access sensitive system configurations.

Dubbed CVE-2025-9133, this flaw affects devices running firmware versions up to V5.40(ABPS.0) and enables unauthorized viewing and downloading of configs even during the two-factor authentication (2FA) process.

cyber security news
Disclosed on August 14, 2025, the issue stems from inadequate command filtering in the web interface, potentially exposing credentials, keys, and network settings to remote exploitation.

The vulnerability arises when a user with 2FA enabled logs into the device’s web portal. Normally, they must enter a one-time PIN via email or an authenticator app to proceed.

However, before verification, the system sends semi-authenticated requests to the backend zysh-cgi binary, which handles configuration queries.

According to Alessandro Sgreccia, who discovered the flaw parallel to CVE-2025-8078, found that attackers can manipulate these requests to inject commands, evading a whitelist that restricts access for unverified users.

Bypassing Via Command Injection
Using tools like Burp Suite, the researcher intercepted POST requests to /cgi-bin/zysh-cgi. These requests typically include benign commands like “show version” or “show users current,” which are whitelisted for partial authentication states (user type 0x14).

The binary performs prefix-based validation, checking only the start of the string against the allowlist. If it matches, the entire command chain is forwarded to the device’s CLI parser, executing the hidden payload without further scrutiny.

Attempts to directly access configs via export-cgi or file_upload-cgi trigger a 302 redirect to the login page, enforcing logout after failed 2FA tries.

But the zysh-cgi endpoint lacks this protection, returning full configuration dumps in JavaScript-serialized responses (e.g., zyshdata arrays) when filter=js2 is set.

Binary analysis of zysh-cgi revealed two execution paths based on user profile: a restricted “engine” for non-admins that skips full validation, allowing the bypass.

Without splitting commands on semicolons or re-validating sub-parts, the flaw turns a read-only query into a full exfiltration vector.

This authorization bypass could enable attackers to harvest passwords, API keys, and routing details, facilitating lateral movement in networks or persistence via config tampering.

Zyxel devices, popular in enterprise and SMB environments for threat protection, amplify the risk especially since the flaw persists even with 2FA active.

Zyxel has not yet issued a patch as of October 2025, but experts recommend immediate mitigations: disable remote web access, enforce strict firewall rules on CGI endpoints, and monitor for anomalous zysh-cgi traffic.

For remediation, vendors should tokenize commands, validate each sub-command individually, and reject chaining entirely. Adding CSRF tokens and rate-limiting could bolster defenses.

As cybersecurity threats evolve, this incident underscores the dangers of incomplete input sanitization in embedded systems. Organizations using Zyxel ATP/USG should audit configurations urgently to prevent data leaks.



#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news

Оригинальная версия на сайте: ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.