Security Blog

    In-depth analysis, research findings, and technical writeups on cybersecurity topics.

    11
    Articles
    23
    Topics

    Featured Articles

    The incorrect permission assignment vulnerability in the PostgreSQL commands of certain USG FLEX H series uOS firmware versions could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system configurations with administrator-level access through a stolen token.

    ZYXEL
    Remote Code Execution
    Exploit
    CVE-2025-1731
    CVE-2025-1732
    uOS 1.31
    22/04/2025
    5 min read

    Recent Articles

    21/10/2025
    0 min read

    Coming soon: CVE-2025-9133

    Writeup of CVE-2025-9133 coming in Oct. 21, 2025.

    21/10/2025
    0 min read

    Coming soon: CVE-2025-8078

    Writeup of CVE-2025-8078 coming in Oct. 21, 2025.

    16/09/2025
    2 min read

    LLM Attack on ZYXEL Nebula AI

    As part of a research project on prompt injection and AI security, the behavior of Zyxel’s Nebula AI chatbot was analyzed. The objective was to evaluate whether the model could be manipulated into disclosing internal information or metadata not intended for end-users.

    LLM Attack
    AI
    ZYXEL
    Chatbot
    25/07/2025
    2 min read

    File Upload Vulnerability in ZYXEL Configuration Migration Tool

    An in-depth walkthrough of how a flawed file upload mechanism in Zyxel’s cloud migration service allowed arbitrary PHP file upload and execution, leading to full remote code execution on the backend infrastructure.

    Web Exploitation
    ZYXEL
    File Upload Vulnerability
    05/03/2025
    3 min read

    CVE-2023-27991: Remote Code Execution in ZYXEL ATP/USG (V5.35)

    This writeup explain how to gain a remote code execution vulnerability in the ZLD product series. The vulnerability could allow attackers to execute arbitrary code on the target system.

    Remote Code Execution
    ZYXEL
    CVE-2023-27991
    ZLD 5.35