firmware automatically upgraded even if auto update is disabled
stefano_tonazzi
Posts: 4
Hi,
yesterday we have found the firmware on two of our usg60 FW updated to version V4.72(AAKY.0) / 2022-04-28 23:20:15, even if auto update feature is not enabled.
This lead to a misconfiguration of our vpn setup ( the port of the
Authorize Link URL Address was modified ).
Does anyone have an explanation for this?
Regards
Stefano
0
All Replies
-
Can you verify when the firmware was updated? A hint could come from the config files, which are updated after the firmware image is deployed into standby partition.
This information could lead to identify if someone may have updated it manually.0 -
Yes, we have checked that, and we are able to verify that it was modified 6 days ago.But we are 100% sure that nobody did it manually.We found out just now that even a third USG was updated.0
-
Worth asking...
According to Zyxel, 4.72 was a security release, for address a CVE vulnerability (more of that).
https://community.zyxel.com/en/discussion/13501/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-ap-controllers-and-aps
This is my setting for not-auto-upgrade firmware on USG40, AFAIK should be the same for your USG60W.
Your USG60W set of devices have auto-reboot enabled? 6 days seems shorter than a week...
Question goes to Zyxel representatives: is there any policy for enforcing updates on devices from no-Nebula enabled devices?
0 -
Hi and thanks for your responses. This is the firmware update configuration from one of the USG60.
As you can see both Auto Update and Auto Reboot are unchecked, so I would assume that only manual upgrades are possible.
Despite that, we found 3 of 4 devices updated, and i am 100% sure nobody did it manually ( one by mistake could happen, but 3 of 4 ? )
0 -
stefano_tonazzi said:Despite that, we found 3 of 4 devices updated, and i am 100% sure nobody did it manually (one by mistake could happen, but 3 of 4?)One manager went ballistic, the other one thanked me and explaining why some tasks were scheduled, even with security updates recently released, telling me to wait until task was assigned to me.I cannot tell that if you might have someone like the older me, eager to avoid security breaches. Maybe there's, maybe not, but worth asking.Still hoping that into italian evening/night some representative could share the status. Recently QNAP pushed a firmware upgrade for a vulnerability. Hope Zyxel didn't do the same thing.
1 -
Hi @stefano_tonazzi,
Just in case, please check if there is any abnormal admin account created on those devices?0 -
Hi,no. There are no abnormal admin account created on the devices.
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight