Common Information
Type Value
Value
rule Zyxel_CVE_2023_33012 {
	meta:
		description = "Zyxel ZTP Config Parser Exploit Attempt"
		path_pattern = "/ztp/cgi-bin/dumpztplog.py"
	strings:
		$vti = "proto=vti"
		$gre = "proto=gre"
		$tmp = "/tmp/"
		$qsr = ".qsr"
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Website 2024-02-21 9 re: Zyxel VPN Series Pre-auth Remote Command Execution - Blog - VulnCheck