newsoft Retweeted Hacker Fantastic
Execution de commandes à distance dans les NAS et les VPN Zyxel. Apparemment connu depuis des années. Pas de correctif pour une bonne partie des équipements affectés.
https://twitter.com/hackerfantastic/status/1232071459201331202 …
newsoft added,
Hacker Fantastic @hackerfantastic
Congratulations to @wdormann & @briankrebs on identifying this stunning bug https://kb.cert.org/vuls/id/498544/
- with a PoC tester that injects "/sbin/halt" to power off an affected device https://kb.cert.org/artifacts/cve-2020-9054.html … #CVE-2020-9054 PoC makes interesting reading, exploit is in rebootnas(); func.
12:22 AM - 26 Feb 2020
0 replies
13 retweets
15 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.