Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Top NAS devices are being targeted by this dangerous malware

  • June 5, 2023
Total
0
Shares
0
0
0


IoT cybersecurity company Sternum has identified a security vulnerability affecting Zyxel Networks’ Linux-operated NAS drives, including NAS326, NAS540, and NAS542 models, running on firmware version 5.21.

Zyxel Networks’ advisory reads: “The post-authentication command injection vulnerability has been found in the web management interface of some NAS versions,” citing firmware 5.21 and previous versions.

Users are being urged to patch their NAS drives with the latest firmware, which is also identified as 5.21, in order to protect their devices.

Zyxel Networks NAS owners urged to apply patch

Specifically, NAS326 owners are being told to update from 5.21 (AAZF.12)C0 to (AAZF.13)C0, NAS540 from (AATB.9)C0 to (AATB.10)C0, and NAS542 from (ABAG.9)C0 to (ABAG.10)C0. The updates are available from the Zyxel website. 

Sternum’s Noam Zhitomirsky, Reuven Yakar, Dean Zavadski, and Amit Serper are credited with notifying the NAS maker of the vulnerability, which was marked as CVE-2023-27988 on May 30, 2023.

In a press release, Sternum said: “Sternum security researchers were in the process of scanning one of the Zyxel NAS units as part of the company’s standard lab deployment process when a “Dangerous String Format” alert was triggered by one of the security logics in the Sternum security platform.”

The problem was pinpointed as being with the ntpdate_date process, which left a vulnerability allowing an authenticated user to execute an arbitrary system command with root privileges on the system. 

Sternum stressed that this could allow hackers to inject remote malware onto unsuspecting NAS drive owners’ devices.

While Zyxel’s quickly-issued patch will fix the issue, Sternum’s researchers believe that other companies’ drives could be vulnerable to similar issues, urging customers and consumers to always keep an eye out for company announcements and apply patches as soon as they become available. 

  • Looking to take your storage entirely off-prem? Check out the best cloud storage providers

Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

How to uninstall Mac apps (and their settings too)

  • June 5, 2023
View Post
Next Article
  • News

Windows 11 reportedly installs optional update without asking – and it’s causing trouble

  • June 5, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Thursday, September 28 (game #612)

  • September 27, 2023
View Post
  • News

9 things announced at the Meta Connect 2023 event

  • September 27, 2023
View Post
  • News

Sony’s PlayStation Chief to Retire Next Year

  • September 27, 2023
View Post
  • News

Plucky CPU maker beats AMD and Intel to become first to offer 320 cores per server — with even bigger models in the pipeline

  • September 27, 2023
View Post
  • News

Counter-Strike 2 has finally released on PC – players can dive in now

  • September 27, 2023
View Post
  • News

macOS Sonoma has a whole host of security fixes – should we be worried?

  • September 27, 2023
View Post
  • News

The Ray-Ban Stories 2 is here with a new design, new specs, and a new name

  • September 27, 2023
View Post
  • News

The Meta Quest 3 is here, and I think it’s the best VR headset yet

  • September 27, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.