Stembolt Threat intelligence startup GreyNoise warned late last month that a critical-rated zero-day vulnerability impacting Zyxel routers was being actively exploited. In an advisory this week, Zyxel said it “recently” became aware of the two vulnerabilities — now formally tracked as CVE-2024-40890 and CVE-2024-40891 — which it says impact multiple end-of-life products. Taiwanese hardware maker Zyxel says it has no plans to release a patch for two actively exploited vulnerabilities affecting potentially thousands of customers. Router maker Zyxel tells customers to replace vulnerable hardware exploited by hackers
markmich4 Wow just makes ya feel all warm and fuzzy with support like that.. lol.. I can understand it's end of life but to tell you to buy new instead, nice sales pitch. Actually I didn't even know Zyxel was still in business! Last time I heard of them was more than 20 years ago helping a friend get dsl and using that brand modem. It wasn't that great of a modem performance wise either. Guess I'm just all in a happy mood this morning! lol :
GrumpyCanadian If I were in that position, this would likely be my reasoning: replace the device? Sure. Buy another Zyxel? Never!
Uncle_Paul It's EOL, why would I expect a company to provide patching support for devices they've said they won't be supporting any longer? As Guy54435 said, you're on your own and knew it when you continued to use an EOL system.