← All CVEs

CVE-2022-0342

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

9.8
CVSS
95.1%
EPSS (exploit prob.)
100th
EPSS percentile
2022-03-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
zyxelusg40_firmware>= 4.20, < 4.71
zyxelusg40all versions
zyxelusg40w_firmware>= 4.20, < 4.71
zyxelusg40wall versions
zyxelusg60_firmware>= 4.20, < 4.71
zyxelusg60all versions
zyxelusg60w_firmware>= 4.20, < 4.71
zyxelusg60wall versions
zyxelzywall_110_firmware>= 4.20, < 4.71
zyxelzywall_110all versions
zyxelzywall_310_firmware>= 4.20, < 4.71
zyxelzywall_310all versions
zyxelzywall_1100_firmware>= 4.20, < 4.71
zyxelzywall_1100all versions
zyxelusg_flex_100_firmware>= 4.50, <= 5.20
zyxelusg_flex_100all versions
zyxelusg_flex_200_firmware>= 4.50, <= 5.20
zyxelusg_flex_200all versions
zyxelusg_flex_500_firmware>= 4.50, <= 5.20
zyxelusg_flex_500all versions
zyxelusg_flex_100w_firmware>= 4.50, <= 5.20
zyxelusg_flex_100wall versions
zyxelusg_flex_700_firmware>= 4.50, <= 5.20
zyxelusg_flex_700all versions
zyxelatp100_firmware>= 4.32, <= 5.20
zyxelatp100all versions
zyxelatp100w_firmware>= 4.32, <= 5.20
zyxelatp100wall versions
zyxelatp200_firmware>= 4.32, <= 5.20
zyxelatp200all versions
zyxelatp500_firmware>= 4.32, <= 5.20
zyxelatp500all versions
zyxelatp700_firmware>= 4.32, <= 5.20
zyxelatp700all versions
zyxelatp800_firmware>= 4.32, <= 5.20
zyxelatp800all versions
zyxelvpn50_firmware>= 4.30, < 5.21
zyxelvpn50all versions
zyxelvpn100_firmware>= 4.30, < 5.21
zyxelvpn100all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-0342