← Back

CVE-2022-30525

Published: May 12, 2022Modified: Oct 27, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Affected (16)

16 products
Usg Flex 100w Firmware
Usg Flex 200 Firmware
Usg Flex 500 Firmware
Usg Flex 700 Firmware
Vpn100 Firmware
Vpn1000 Firmware
Vpn300 Firmware
Vpn50 Firmware
Atp100 Firmware
Atp100w Firmware
Atp200 Firmware
Atp500 Firmware
Atp700 Firmware
Atp800 Firmware
Usg Flex 50w Firmware
Usg20w Vpn Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.00 to 5.30
Running on/withPlatform Versions
Zyxel
Usg Flex 100w
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.00 to 5.30
Running on/withPlatform Versions
Zyxel
Usg Flex 200
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.00 to 5.30
Running on/withPlatform Versions
Zyxel
Usg Flex 500
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.00 to 5.30
Running on/withPlatform Versions
Zyxel
Usg Flex 700
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.60 to 5.30
Running on/withPlatform Versions
Zyxel
Vpn100
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.60 to 5.30
Running on/withPlatform Versions
Zyxel
Vpn1000
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.60 to 5.30
Running on/withPlatform Versions
Zyxel
Vpn300
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.60 to 5.30
Running on/withPlatform Versions
Zyxel
Vpn50
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp100
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp100w
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp200
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp500
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp700
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Atp800
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Usg Flex 50w
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 5.10 to 5.30
Running on/withPlatform Versions
Zyxel
Usg20w Vpn
All versions

References (11)

Source: security@zyxel.com.tw
Third Party AdvisoryVDB Entry
Source: security@zyxel.com.tw
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.