Hubbry Logo
search button
Sign in
ZyNOS
ZyNOS
Comunity Hub
History
arrow-down
starMore
arrow-down
bob

Bob

Have a question related to this hub?

bob

Alice

Got something to say related to this hub?
Share it here.

#general is a chat channel to discuss anything related to the hub.
Hubbry Logo
search button
Sign in
ZyNOS
Community hub for the Wikipedia article
logoWikipedian hub
Welcome to the community hub built on top of the ZyNOS Wikipedia article. Here, you can discuss, collect, and organize anything related to ZyNOS. The purpose of the hub is to connect people, foster deeper...
Add your contribution
ZyNOS

ZyNOS is the proprietary operating system used on network devices made by Zyxel Communications.[1] The name is a contraction of Zyxel and Network Operating System (NOS).

History

[edit]

Zyxel first introduced ZyNOS in 1998.[2]

Versions

[edit]

Zyxel released ZyNOS version 4.0 for their GS2200 series 24 and 48 port ethernet switches in April, 2012.[3] It appears that versions differ between Zyxel products.

Access methods

[edit]

Web and/or command-line interface (CLI) depending on the device. Web access is accomplished by connecting an Ethernet cable between a PC and an open port on the device and entering the IP address of the device into the Web browser.[4] An RS-232 serial console port is provided on some devices for CLI access, which is accomplished by using SSH or telnet.[5]

CLI command types

[edit]

Listed below are the categories that the CLI commands are grouped by.[6]

  • system-related commands
  • exit command
  • Ethernet-related commands
  • WAN-related commands
  • WLAN-related commands
  • IP-related commands
  • PPP-related commands
  • bridge-related commands
  • RADIUS-related commands
  • 802.1x-related commands
  • firewall-related commands
  • configuration-related commands
  • SMT-related commands.

Web Configurator

[edit]

The Web Configurator is divided into the following categories:[7][4]

  • basic settings
  • advanced application
  • IP application
  • management

Security advisories

[edit]

As of January 2014 a ZyNOS ROM-0 vulnerability has been identified.[8] This vulnerability allowed attacker to download router's configuration (ROM-0 file) without any type of authentication required. Such configuration file can be later decompressed[9][10] to expose router's administrator password, ISP password, wireless password etc.

As of March 2014, Danish computer security company Secunia reports no unpatched advisories or vulnerabilities on ZyNOS version 4.x.[11]

As of March 2014, Secunia reports seven advisories and six vulnerabilities on ZyNOS version 3.x. Five advisories are unpatched; Secunia rates the most severe unpatched advisory as less critical.[12]

As of January 2015, a DNS vulnerability has been found in certain ZyNOS firmware versions. The versions that are affected have not been narrowed down. The attack can be done from a remote location regardless if the user interface is accessible from the outside of a LAN.[13]

References

[edit]
  1. ^ Tseng, Mickey. "ZyNOS General FAQ". Zyxeltech.de. Archived from the original on 2015-02-02. Retrieved 2014-03-07.
  2. ^ "Timeline". Archived from the original on 2012-05-31. Retrieved 2012-06-06.
  3. ^ "ZYXEL LAUNCHES IPv6 UPGRADE FOR BUSINESS SECURITY GATEWAYS AND ETHERNET SWITCHES". Archived from the original on 2012-05-12. Retrieved 2012-06-06.
  4. ^ a b "ZyBook2.book" (PDF). Archived from the original (PDF) on 2022-01-21. Retrieved 2014-03-07.
  5. ^ "Ethernet Switch Reference Guide V3.90 (Nov 2008)" (PDF). Archived from the original (PDF) on 2022-01-21. Retrieved 2014-03-07.
  6. ^ Tseng, Mickey. "ZyNOS CI Command List". Zyxeltech.de. Archived from the original on 2015-02-02. Retrieved 2014-03-07.
  7. ^ "FTP link" (PDF). ftp2.zyxel.com (FTP).[dead ftp link] (To view documents see Help:FTP)
  8. ^ Nasro (2014-01-11). "How I saved your a** from the ZynOS (rom-0) attack !! ( Full disclosure )". root@Nasro. Retrieved 2019-08-18.
  9. ^ "ZyNOS ROM-0 DECODER".
  10. ^ Soo, Jacob (2015-05-12), GitHub - jacobsoo/ROM0_Decoder: Rom0 Decoder., retrieved 2019-08-18
  11. ^ "ZyXEL ZyNOS 4.x". Secunia. Retrieved 2014-03-07.
  12. ^ "ZyXEL ZyNOS 3.x". Secunia. Retrieved 2014-03-07.
  13. ^ "DNS hijacking flaw affects D-Link DSL router, possibly other devices". Lucian Constantin. Retrieved 2015-01-30.