A new vulnerability found in Zyxel VPN and Firewall products allows attackers to pass un-sanitized input to the back end and execute arbitrary code. This is a nasty exploit that's already gotten its own module in Metasploit, so let's dive right in and talk about everything we know about CVE-2022-30525 AKA (according to me) the 'nobody exploit'.
⭐️ Find me at:
Website - https://studio-sec.com/
Twitter - / sec_studio
Buy Merch - https://studiosec.creator-spring.com/
Discord - / discord
Medium - / studiosec
BMAC - https://www.buymeacoffee.com/studiosec
All My Other Links - https://wlo.link/@studiosec
Business Email - [email protected]
Interested in starting a lab or sprucing up your home office? Check out these affiliate links for cool things I highly recommend! These also go to help support the channel!
👇👇👇👇👇👇👇👇👇👇👇
https://kit.co/studiosec
Note: I receive a small commission from any purchases of any of the gear shown in the affiliate link above. This supports the channel and keeps the content free!
#studiosec #cybersecurity #exploit #vulnerability #cve #firewall #zyxel #vpn
Timestamps:
0:00 When Firewalls Get Hacked…
1:41 CVE-2022-30525 Explained
2:45 What Is ‘Nobody’ In Linux?
4:15 CVE-2022-30525 Threat Landscape
5:15 Disclosure Timeline For CVE-2022-30525
Ref:
https://www.rapid7.com/blog/post/2022... 😎 Enjoy the quality of this video? Consider getting what I use to make this content!
https://amzn.to/3AjG1VC iPhone 13 Pro Max
https://amzn.to/3zTKr40 Apple M1 Pro Mac
https://amzn.to/3QCBouN TONOR Mic
https://amzn.to/3AinOYi iPhone Recording Tripod
https://amzn.to/3bKit2J Ring Light