CVE-2022-26413
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD
Description
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
Affected (34)
Products: Zyxel: Vmg3312 T20a Firmware, Emg3525 T50b Firmware, Emg5523 T50b Firmware, Emg5723 T50k Firmware, Emg6726 B10a Firmware, Vmg1312 T20b Firmware, Vmg3625 T50b Firmware, Vmg3927 B50a Firmware, Vmg3927 B50b Firmware, Vmg3927 B60a Firmware, Vmg3927 T50k Firmware, Vmg4927 B50a Firmware, Vmg8623 T50b Firmware, Vmg8825 B50a Firmware, Vmg8825 B50b Firmware, Vmg8825 T50k Firmware, Vmg8825 B60a Firmware, Vmg8825 B60b Firmware, Xmg3927 B50a Firmware, Xmg8825 B50a Firmware, Dx5401 B0 Firmware, Ex3510 B0 Firmware, Ex5401 B0 Firmware, Ex5501 B0 Firmware, Ax7501 B0 Firmware, Ep240p Firmware, Pm7300 T0 Firmware, Pmg5317 T20b Firmware, Pmg5617ga Firmware, Pmg5617 T20b2 Firmware, Pmg5622ga Firmware, Px7501 B0 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.30(abfx.5)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3312 T20a | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abpm.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg3525 T50b | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abpm.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg5523 T50b | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abom.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg5723 T50k | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.13\(abnp.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Emg6726 B10a | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(absb.5\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg1312 T20b | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abpm.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3625 T50b | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3927 B50a | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.13\(ably.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3927 B50b | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3927 B60a | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abom.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg3927 T50k | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.13\(ably.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg4927 B50a | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abpm.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8623 T50b | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 B50a | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abny.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 B50b | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.50\(abom.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 T50k | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 B60a | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abny.7\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Vmg8825 B60b | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Xmg3927 B50a | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abmt.6\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Xmg8825 B50a | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abyo.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Dx5401 B0 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abup.4\)c1 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex3510 B0 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abyo.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5401 B0 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abry.2\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ex5501 B0 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abpc.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ax7501 B0 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.40\(abh.0\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Ep240p | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.42\(acbc.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pm7300 T0 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.40\(abki.4\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5317 T20b | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.40\(abna.2\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5617ga | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.41\(acbb.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5617 T20b2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.40\(abnb.2\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Pmg5622ga | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.17\(abpc.1\)c0 |
| Running on/with | Platform Versions |
|---|---|
Zyxel Px7501 B0 | All versions |
References (2)
Source: security@zyxel.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.