Over 1 lakh Zyxel firewalls, VPN gateways at hacking risk: Report


New Delhi, Jan 2 (IANS): Dutch cybersecurity researchers have discovered backdoor account in over 1 lakh networking devices manufactured by Taiwan-based company Zyxel, that can grant hackers access to those vulnerable devices and put data at risk.

The backdoor account, discovered by a team of Dutch security researchers from Eye Control, is considered as bad as it gets in terms of vulnerabilities, ZDNet reported on Saturday.

"Affected models include many of Zyxel's top products from its line of business-grade devices, usually deployed across private enterprise and government networks," the report mentioned.

More than 1 lakh Zyxel firewalls, VPN gateways and access point controllers were reported to have been compromised by the hardcoded admin-level backdoor account.

Zyxel has issued a security patch "for the hardcoded credential vulnerability of firewalls and AP controllers recently reported by researchers from Eye Control Netherlands".

Users are advised to install the applicable firmware updates for optimal protection, the company said in an update.

State-sponsored hackers and ransomware groupd can abuse this backdoor account to access vulnerable devices.

"Affected models include many of Zyxel's top products from its line of business-grade devices, usually deployed across private enterprise and government networks," the report mentioned on Friday.

 

  

Top Stories


Leave a Comment

Title: Over 1 lakh Zyxel firewalls, VPN gateways at hacking risk: Report



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.