← All CVEs

CVE-2022-30525

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-16Remediation due 2022-06-06

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

9.8
CVSS
99.9%
EPSS (exploit prob.)
100th
EPSS percentile
2022-05-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
zyxelusg_flex_100w_firmware>= 5.00, < 5.30
zyxelusg_flex_100wall versions
zyxelusg_flex_200_firmware>= 5.00, < 5.30
zyxelusg_flex_200all versions
zyxelusg_flex_500_firmware>= 5.00, <= 5.30
zyxelusg_flex_500all versions
zyxelusg_flex_700_firmware>= 5.00, < 5.30
zyxelusg_flex_700all versions
zyxelvpn100_firmware>= 4.60, < 5.30
zyxelvpn100all versions
zyxelvpn1000_firmware>= 4.60, < 5.30
zyxelvpn1000all versions
zyxelvpn300_firmware>= 4.60, < 5.30
zyxelvpn300all versions
zyxelvpn50_firmware>= 4.60, < 5.30
zyxelvpn50all versions
zyxelatp100_firmware>= 5.10, < 5.30
zyxelatp100all versions
zyxelatp100w_firmware>= 5.10, < 5.30
zyxelatp100wall versions
zyxelatp200_firmware>= 5.10, < 5.30
zyxelatp200all versions
zyxelatp500_firmware>= 5.10, < 5.30
zyxelatp500all versions
zyxelatp700_firmware>= 5.10, < 5.30
zyxelatp700all versions
zyxelatp800_firmware>= 5.10, < 5.30
zyxelatp800all versions
zyxelusg_flex_50w_firmware>= 5.10, < 5.30
zyxelusg_flex_50wall versions
zyxelusg20w-vpn_firmware>= 5.10, < 5.30
zyxelusg20w-vpnall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-30525