Zyxel is warning {that a} unhealthy safety signature replace is inflicting vital errors for USG FLEX or ATP Collection firewalls, together with placing the system right into a boot loop.
“We have discovered a difficulty affecting a number of units that will trigger reboot loops, ZySH daemon failures, or login entry issues,” warns a brand new Zyxel advisory.
“The system LED may flash. Please be aware that is not associated to a CVE or safety problem.”
Zyxel says the problems are brought on by a failure in an Software Signature Replace for its cybersecurity options that was pushed out on 1/24 via 1/25 at night time.
Units that acquired the defective replace are actually experiencing a variety of points, together with:
- Machine Error: Mistaken CLI command, system timeout or system logout.
- Unable to login to ATP/USG FLEX through internet GUI: 504 Gateway timeout.
- CPU utilization is excessive.
- In Monitor > Log, the message “ZySH daemon is busy” appeared.
- Unable to enter any instructions on console.
- Coredump messages seem on console.
Zyxel says solely USG FLEX or ATP Collection (ZLD Firmware Variations) firewalls with lively safety licenses are impacted. Units on the Nebula platform or USG FLEX H (uOS) sequence should not affected.
As first reported by Born Metropolis, the one strategy to repair the difficulty is to have bodily entry to the firewall and to connect with the console through an RS232 serial cable.
“This restoration requires a console cable and have to be carried out on-site. Whereas it isn’t best, it is the one assured resolution for this problem,” reads the advisory.

Supply: Zyxel
Admins will now must conduct a sequence of steps to revive the firewall, together with backing up the configuration, downloading and making use of a particular firmware, after which connecting through the online GUI to revive the backed-up configuration file.
Zyxel has shared detailed steps in its advisory, and it’s extremely advisable that admins evaluation them earlier than trying to recuperate units.
For purchasers who’ve additional questions or want help, Zyxel will probably be internet hosting a Microsoft Groups Open Query Session on Saturday January twenty fifth from 9am – 12pm and 1pm – 5pm (GMT +1).
BleepingComputer has contacted Zyxel with questions in regards to the incident, however no reply was instantly acquired.