Zyxel security advisory for CRLF injection vulnerability in some legacy firewalls
Summary
Zyxel is aware of a CRLF injection vulnerability in legacy USG100, USG200, USG300, USG20W, USG20, and USG50 firewalls. Since all of the affected models have reached end-of-vulnerability-support, users are advised to replace them with newer-generation models for optimal protection.
What is the vulnerability?
The CRLF injection vulnerability is due to improper input sanitization in the CGI program of some legacy Zyxel firewalls. This flaw could be used to conduct malicious attacks, such as cross-site scripting (XSS) and web cache poisoning.
What versions are vulnerable—and what should you do?
After a thorough investigation, we’ve identified only some legacy firewalls as being affected. The affected models, namely USG20, USG20W, USG50, USG100, USG200, and USG300, all entered end-of-vulnerability-support many years earlier. In accordance with industry product life cycle management practices, Zyxel advises customers to replace these legacy products with newer-generation models.
Got a question?
Please contact your local service rep or visit Zyxel’s forum for further information or assistance.
Acknowledgments and commentary
Thanks to Darren & Pedro from CipherTechs for reporting the issue to us.
Revision history
2022-06-07: Initial release
Comments
-
all entered end-of-vulnerability-support...
Please clarify the statement.
Is end-of-vulnerability-support equal to end-of-life?
In this case I should find all the listed products here https://webservice.zyxel.com/end-of-life, but I do not.
USG20 refers to USG20-VPN & USG20W-VPN? (some links in the comment would make this advisory m,ore helpful).
It would be helpful to display the end-of-life in your product pages. At least I have found nothing here: https://www.zyxel.com/de/de/products_services/Business-Firewall-USG20-VPN-USG20W-VPN/specifications
0 -
@Vennemeyer AFAIK USG20-VPN is not the same product of USG20.
USG20 can load firmware 3.x only.
USG20-VPN started with firmware 4.x and now receives firmware 5.x0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 131 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 180 USG FLEX H Series
- 258 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 236 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight