CRITICAL

CVE-2022-30525

Zyxel Usg Flex 100w Firmware 2022-05-12 CVSS v3.1
CVSS
9.8
KEV

Description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Summary dbcve.org

An OS command injection vulnerability exists in the CGI program of multiple Zyxel firewall/UTM appliances (USG FLEX, ATP, VPN series) running affected firmware versions, allowing an unauthenticated remote attacker to modify specific files and execute arbitrary OS commands on the device with elevated privileges.

Mitigation

Upgrade affected Zyxel devices to a fixed firmware version released by the vendor (post 5.21 Patch 1) and restrict access to the management web interface (e.g., bind to trusted networks, disable WAN/HTTP management, use ACLs) until the patch is applied.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

99.94%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE