[Linux expoit] - CVE-2026-31431
Master Member
Hello everyone,
I recently came to know this new CVE:
Some of devices are affected by this?
I have the USG Flex 200HP firewall and NWA130BE wireless. Are these devices affected by this bug by any chance?
Thank you
Accepted Solution
-
This CVE matters mainly for:
- Linux servers (Ubuntu, Debian, RHEL, etc.)
- Kubernetes / Docker hosts
- Shared systems (CI/CD, VPS, multi-user boxes)
Because:
It needs a local unprivileged user to run code
Your firewall/AP:
Don’t expose that attack surface
Don’t allow arbitrary user code executionYou are at risk if you have something like this behind the firewall:
- Linux NAS with SSH users
- Proxmox / ESXi with Linux VMs
- Docker host running public containers
- CI runner / dev box
- VPS / cloud VM
0
All Replies
-
That’s a really interesting question.
I know that this bug is an LPE then it can escalate priviledges, so it has to be launched via SSH with a local access to that. Also a standard user.
Anyway with a RCE exposed on web services it could bypass the rest of the process without touching the firewall/AP.
I’ll follow this thread, that’s nice
0 -
This CVE matters mainly for:
- Linux servers (Ubuntu, Debian, RHEL, etc.)
- Kubernetes / Docker hosts
- Shared systems (CI/CD, VPS, multi-user boxes)
Because:
It needs a local unprivileged user to run code
Your firewall/AP:
Don’t expose that attack surface
Don’t allow arbitrary user code executionYou are at risk if you have something like this behind the firewall:
- Linux NAS with SSH users
- Proxmox / ESXi with Linux VMs
- Docker host running public containers
- CI runner / dev box
- VPS / cloud VM
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 224 Nebula Ideas
- 130 Nebula Status and Incidents
- 6.6K Security
- 640 USG FLEX H Series
- 357 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7K Consumer Product
- 303 Service & License
- 494 News and Release
- 93 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 88 About Community
- 109 Security Highlight
Zyxel Employee
Guru Member