Zyxel security advisory for insecure folder permissions of ZON Utility
CVE: CVE-2020-27667
Summary
Zyxel has released a patch for the incorrect folder permission vulnerability of Zyxel One Network (ZON) Utility recently reported by researchers from ECSC Group UK. Users are advised to install the latest software version for optimal protection.
What is the vulnerability?
The permission of an installation folder in ZON Utility was misconfigured to give incorrect default permissions for the group “Everyone”, which could be used for privilege escalation on an installed computer. However, the vulnerability is more likely to affect shared computers on which multiple accounts exist, while ZON Utility is mostly used on personal computers by IT staff and individuals.
What versions are vulnerable—and what should you do?
After a thorough investigation, we confirmed that the vulnerability affects only ZON Utility versions V2.1.4 and earlier, and we have released a patch in ZON Utility version V2.1.5 to address the issue. Note that the vulnerability does not impact devices configured using ZON Utility. For optimal protection, we urge users to install the applicable updates.
Please contact your local service rep for further information or assistance. If you’ve found a vulnerability, we want to work with you to fix it—contact security@zyxel.com.tw, and we’ll get right back to you.
Thanks to Richard Davy and Neil Graham of ECSC Group UK for reporting the issue to us.
2021-1-11: Initial release
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 218 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 245 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight