Zyxel’s Critical Router Vulnerability Exploited via Malicious Cookies

Amber | Vulnerability Report

Zyxel has released security updates to address a critical vulnerability tracked as CVE-2024-7261 affecting multiple models of its business routers and access points (APs). This vulnerability allows unauthenticated attackers to perform OS command injection by sending a specially crafted cookie to the vulnerable devices. If exploited, this flaw could enable attackers to potentially compromise the security and functionality of the affected devices.

Reduce real exposure. Not just vulnerability volume.