Zyxel Firewalls Borked By Buggy Update, On-site Access Required For Fix

Zyxel customers are dealing with a range of issues including reboot loops after an update on Friday went awry.

The Taiwanese vendor updated application signatures for some of its firewalls between Friday and Saturday but insists the issues are unrelated to security or specific vulnerabilities.

"We've found an issue affecting a few devices that may cause reboot loops, ZySH daemon failures, or login access problems," Zyxel's advisory reads. "The system LED may also flash. Please note this is not related to a CVE or security issue.

"The issue stems from a failure in the Application Signature Update, not a firmware upgrade. To address this, we've disabled the application signature on our servers, preventing further impact on firewalls that haven't loaded the new signature versions."

In addition to boot loops, some users are experiencing glitches such as being unable to enter console commands, unusually high CPU usage, and various other error messages.

The firewalls affected include USG Flex boxes and ATP Series devices running ZLD firmware versions – installations that have active security licenses and dedicated signature updates enabled in on-premises/standalone mode.

Those running on the Nebula platform, on USG Flex H (uOS), and those without valid security licenses are not affected.

It also says that currently, there is only one way to get around this, and it is "not ideal."

The "not ideal" part is that sysadmins will need physical access to the firewall and a Console/RS232 cable to begin the recovery process.

Zyxel details each step in its advisory, but it involves creating a backup file before installing the new firmware.

There are no remote options available, the vendor said. It alluded to potentially available approaches that might work in "very rare" cases, but even then, they might lead to other issues such as losing config files, so they aren't recommended or even detailed.

Zyxel warned that those with systems running in Device-HA mode should contact Zyxel support directly for tailored assistance.

Support agents are available via phone and web chat for admins needing assistance to get their boxes back online. Zyxel also reopened its Microsoft Teams channel today to address customer needs. ®

RECENT NEWS

From Chip War To Cloud War: The Next Frontier In Global Tech Competition

The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more

The High Stakes Of Tech Regulation: Security Risks And Market Dynamics

The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more

The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics

Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more

The Data Crunch In AI: Strategies For Sustainability

Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more

Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser

After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more

LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue

In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more