peter bassill · operator
$ cve CVE-2022-0342 JSON

CVE-2022-0342

9.8
CRITICAL · CVSS 3.1 · EPSS 95.1% (pctl 100)

Patch early

EPSS 95.1% — above the 10% action threshold.

Description

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS95.13% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2022-03-28
Last modified2026-06-17

Affected (40)

VendorProduct
zyxelatp100
zyxelatp100 firmware
zyxelatp100w
zyxelatp100w firmware
zyxelatp200
zyxelatp200 firmware
zyxelatp500
zyxelatp500 firmware
zyxelatp700
zyxelatp700 firmware
zyxelatp800
zyxelatp800 firmware
zyxelusg flex 100
zyxelusg flex 100 firmware
zyxelusg flex 100w
zyxelusg flex 100w firmware
zyxelusg flex 200
zyxelusg flex 200 firmware
zyxelusg flex 500
zyxelusg flex 500 firmware
zyxelusg flex 700
zyxelusg flex 700 firmware
zyxelusg40
zyxelusg40 firmware
zyxelusg40w
zyxelusg40w firmware
zyxelusg60
zyxelusg60 firmware
zyxelusg60w
zyxelusg60w firmware
zyxelvpn100
zyxelvpn100 firmware
zyxelvpn50
zyxelvpn50 firmware
zyxelzywall 110
zyxelzywall 110 firmware
zyxelzywall 1100
zyxelzywall 1100 firmware
zyxelzywall 310
zyxelzywall 310 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD