References https://www.ddpoc.com/DVB-2026-11103.html https://www.ddpoc.com/poc/DVB-2023-5285.html https://cybernews.com/security/keenetic-router-data-leak-puts-users-at-risk/ https://www.vicarius.io/vsociety/posts/exploiting-cve-2024-4022-information-disclosure-in-keenetic-router https://securityaffairs.com/188501/security/critical-zyxel-router-flaw-exposed-devices-to-remote-attacks.html https://www.bleepingcomputer.com/news/security/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/
Related VulnerabilitiesPoCCVE-2018-19326: Zyxel VMG1312-B10D 5.13AAXA.8 - Local File InclusionPoCCVE-2019-12581: Zyxel ZyWal/USG/UAG Devices - Cross-Site ScriptingPoCCVE-2019-12583: Zyxel ZyWall UAG/USG - Account Creation AccessPoCCVE-2019-9955: Zyxel - Cross-Site ScriptingPoCCVE-2020-29583: ZyXel USG - Hardcoded CredentialsPoCCVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code ExecutionPoCCVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication BypassPoCCVE-2021-46387: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site ScriptingPoCCVE-2022-0342: Zyxel - Authentication BypassPoCCVE-2022-30525: Zyxel Firewall - OS Command InjectionPoCCVE-2024-29972: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor AccountPoCCVE-2024-29973: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection