<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zyxel Vulnerabilities - NR5103E affected in Broadband</title>
    <link>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9615#M1308</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Just come across the following Zyxel page that's been updated recently, with mention of some vulnerabilities with their hardware:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.zyxel.com/en/discussion/15553/zyxel-security-advisory-for-command-injection-buffer-overflow-of-cpe-fiber-onts-wifi-extenders" target="_blank" rel="noopener"&gt;https://community.zyxel.com/en/discussion/15553/zyxel-security-advisory-for-command-injection-buffer-overflow-of-cpe-fiber-onts-wifi-extenders&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The NR5103E is listed as being affected by one of the vulnerabilities in the list and says this for the NR5103E:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Hotfix available now&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Standard firmware V1.00(ACDJ.0)C0 in Apr. 2023"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see our current firmware version is '&lt;/SPAN&gt;V1.00(ACBJ.0)b12', and as far as I'm aware, when it comes to Zyxel the 'B' firmware's are beta firmware's and 'C' firmware's are stable/non-beta, so I can only assume that the firmware we are on is older (and beta) than the one listed above and as such is likely affected by the mentioned vulnerability.&lt;/P&gt;&lt;P&gt;Little confused that they say 'Hotfix available now' but then next to the firmware version it says 'Apr. 2023'...not sure if that's just a typo or something but it does look like they have fixed this and released a hotfix/updated firmware for the NR5103E.&lt;/P&gt;&lt;P&gt;Can you confirm you are aware of this and looking to push the firmware update out to us?&lt;/P&gt;&lt;P&gt;FYI&amp;nbsp;&lt;a href="https://community.three.co.uk/t5/user/viewprofilepage/user-id/6"&gt;@JonathanB&lt;/a&gt; as this may be great time to enable the cell locking options for us at the same time&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face_with_tongue:"&gt;😜&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2023 19:09:29 GMT</pubDate>
    <dc:creator>crypt0ninja</dc:creator>
    <dc:date>2023-02-10T19:09:29Z</dc:date>
    <item>
      <title>Zyxel Vulnerabilities - NR5103E affected</title>
      <link>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9615#M1308</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Just come across the following Zyxel page that's been updated recently, with mention of some vulnerabilities with their hardware:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.zyxel.com/en/discussion/15553/zyxel-security-advisory-for-command-injection-buffer-overflow-of-cpe-fiber-onts-wifi-extenders" target="_blank" rel="noopener"&gt;https://community.zyxel.com/en/discussion/15553/zyxel-security-advisory-for-command-injection-buffer-overflow-of-cpe-fiber-onts-wifi-extenders&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The NR5103E is listed as being affected by one of the vulnerabilities in the list and says this for the NR5103E:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Hotfix available now&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Standard firmware V1.00(ACDJ.0)C0 in Apr. 2023"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see our current firmware version is '&lt;/SPAN&gt;V1.00(ACBJ.0)b12', and as far as I'm aware, when it comes to Zyxel the 'B' firmware's are beta firmware's and 'C' firmware's are stable/non-beta, so I can only assume that the firmware we are on is older (and beta) than the one listed above and as such is likely affected by the mentioned vulnerability.&lt;/P&gt;&lt;P&gt;Little confused that they say 'Hotfix available now' but then next to the firmware version it says 'Apr. 2023'...not sure if that's just a typo or something but it does look like they have fixed this and released a hotfix/updated firmware for the NR5103E.&lt;/P&gt;&lt;P&gt;Can you confirm you are aware of this and looking to push the firmware update out to us?&lt;/P&gt;&lt;P&gt;FYI&amp;nbsp;&lt;a href="https://community.three.co.uk/t5/user/viewprofilepage/user-id/6"&gt;@JonathanB&lt;/a&gt; as this may be great time to enable the cell locking options for us at the same time&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face_with_tongue:"&gt;😜&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 19:09:29 GMT</pubDate>
      <guid>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9615#M1308</guid>
      <dc:creator>crypt0ninja</dc:creator>
      <dc:date>2023-02-10T19:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Zyxel Vulnerabilities - NR5103E affected</title>
      <link>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9720#M1348</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.three.co.uk/t5/user/viewprofilepage/user-id/4292"&gt;@crypt0ninja&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thanks for flagging this up. I've checked in with my contacts and been advised that the current B12 firmware includes the required resolutions to address the vulnerabilities mentioned, so all Three supplied NR5103E are already covered.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 11:46:41 GMT</pubDate>
      <guid>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9720#M1348</guid>
      <dc:creator>JonathanB</dc:creator>
      <dc:date>2023-02-14T11:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Zyxel Vulnerabilities - NR5103E affected</title>
      <link>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9721#M1349</link>
      <description>&lt;P&gt;Appreciate the confirmation! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 12:08:37 GMT</pubDate>
      <guid>https://community.three.co.uk/t5/Broadband/Zyxel-Vulnerabilities-NR5103E-affected/m-p/9721#M1349</guid>
      <dc:creator>crypt0ninja</dc:creator>
      <dc:date>2023-02-14T12:08:37Z</dc:date>
    </item>
  </channel>
</rss>

