CVE-2022-30525
Description
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
Summary dbcve.org
An OS command injection vulnerability exists in the CGI program of multiple Zyxel firewall/UTM appliances (USG FLEX, ATP, VPN series) running affected firmware versions, allowing an unauthenticated remote attacker to modify specific files and execute arbitrary OS commands on the device with elevated privileges.
Mitigation
Upgrade affected Zyxel devices to a fixed firmware version released by the vendor (post 5.21 Patch 1) and restrict access to the management web interface (e.g., bind to trusted networks, disable WAN/HTTP management, use ACLs) until the patch is applied.