{"id":33600,"date":"2020-02-26T21:40:16","date_gmt":"2020-02-26T21:40:16","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/"},"modified":"2020-02-26T21:40:16","modified_gmt":"2020-02-26T21:40:16","slug":"zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/","title":{"rendered":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2020\/02\/26\/shutterstock_firewall_broken.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Zyxel&#8217;s network storage boxes, business VPN gateways, firewalls, and, er, security scanners can be remotely hijacked by any miscreant, due to a devastating security hole in the firmware.<\/p>\n<p>The devices&#8217; weblogin.cgi program fails to sanitize user input, allowing anyone who can reach one of these vulnerable machines, over the network or across the internet, can silently inject and execute arbitrary commands as a root superuser with no authentication required. That would be a total compromise. It&#8217;s a 10 out of 10 in terms of severity.<\/p>\n<p>As its name suggests, weblogin.cgi is part of the built-in web-based user interface provided by the firmware, and the commands can be injected via GET or POST HTTP requests.<\/p>\n<p>If a miscreant can&#8217;t directly connect to a vulnerable Zyxel device, &#8220;there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable device,&#8221; <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/498544\/\">noted<\/a> Carnegie Mellon&#8217;s CERT Coordination Center in its advisory on the matter.<\/p>\n<p>&#8220;For example, simply visiting a website can result in the compromise of any Zyxel device that is reachable from the client system.&#8221;<\/p>\n<p>Here&#8217;s the affected equipment, which will need patching:<\/p>\n<ul>\n<li><strong>Network-connected storage devices:<\/strong> NAS326, NAS520, NAS540, NAS542<\/li>\n<li><strong>&#8220;Advanced&#8221; security firewalls:<\/strong> ATP100, ATP200, ATP500, ATP800<\/li>\n<li><strong>Security firewalls and gateways:<\/strong> USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200, VPN50, VPN100, VPN300, VPN1000, ZyWALL110, ZyWALL310, and ZyWALL1100<\/li>\n<\/ul>\n<p>Fixes can be fetched and installed <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.zyxel.com\/support\/remote-code-execution-vulnerability-of-NAS-products.shtml\">from Zyxel&#8217;s website<\/a>. Meanwhile, the NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2 models are no longer supported, and thus no patches are available, but are still vulnerable. The security bug (CVE-2020-9054) is trivial to exploit, unfortunately.<\/p>\n<p>&#8220;Command injection within a login page is about as bad as it gets and the lack of any cross-site request forgery token makes this vulnerability particularly dangerous,&#8221; Craig Young, a researcher with security house Tripwire, told <em>The Register<\/em> earlier today. &#8220;JavaScript running in the browser is enough to identify and exploit vulnerable devices on the network.&#8221;<\/p>\n<p>Speaking of bad, exploit code is <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/krebsonsecurity.com\/2020\/02\/zyxel-fixes-0day-in-network-storage-devices\/\">already on sale<\/a> for $20,000 in underground forums, and the patched firmware is delivered via unencryped FTP, which can be meddled with by network eavesdroppers.<\/p>\n<p>&#8220;Be cautious when updating firmware on affected devices, as the Zyxel firmware upgrade process both uses an insecure channel (FTP) for retrieving updates, and the firmware files are only verified by checksum rather than cryptographic signature,&#8221; CERT-CC warned.<\/p>\n<p>&#8220;For these reasons, any attacker that has control of DNS or IP routing may be able to cause a malicious firmware to be installed on a Zyxel device.&#8221;<\/p>\n<p>If you can&#8217;t patch your Zyxel device, bin it \u2013 especially if it&#8217;s facing the internet. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1901\/-8266\/quit-your-addiction-to-storage?td=wptl1901\">Quit your addiction to storage<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/go.theregister.co.uk\/feed\/www.theregister.co.uk\/2020\/02\/26\/zyxel_security_hole\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s 2020 and pre-auth, superuser command injection is still a thing Zyxel&#8217;s network storage boxes, business VPN gateways, firewalls, and, er, security scanners can be remotely hijacked by any miscreant, due to a devastating security hole in the firmware.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":33601,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-33600","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-02-26T21:40:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"833\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now\",\"datePublished\":\"2020-02-26T21:40:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/\"},\"wordCount\":477,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/\",\"name\":\"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg\",\"datePublished\":\"2020-02-26T21:40:16+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/03\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg\",\"width\":833,\"height\":500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/","og_locale":"en_US","og_type":"article","og_title":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-02-26T21:40:16+00:00","og_image":[{"width":833,"height":500,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now","datePublished":"2020-02-26T21:40:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/"},"wordCount":477,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/","url":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/","name":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg","datePublished":"2020-02-26T21:40:16+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/03\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now.jpg","width":833,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/zyxel-storage-firewall-vpn-security-boxes-have-a-give-anyone-on-the-internet-root-hole-patch-right-now\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Zyxel storage, firewall, VPN, security boxes have a give-anyone-on-the-internet-root hole: Patch right now"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/33600","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=33600"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/33600\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/33601"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=33600"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=33600"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=33600"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}