CVE-2022-30525 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-06.
Description
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.94% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2022-06-06 |
| Public exploit | yes |
| Published | 2022-05-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zyxel Multiple Firewalls OS Command Injection Vulnerability |
|---|---|
| Added | 2022-05-16 |
| Due | 2022-06-06 |
| Vendor / product | Zyxel / Multiple Firewalls |
| Ransomware use | none reported |
Affected (32)
| Vendor | Product |
|---|---|
| zyxel | atp100 |
| zyxel | atp100 firmware |
| zyxel | atp100w |
| zyxel | atp100w firmware |
| zyxel | atp200 |
| zyxel | atp200 firmware |
| zyxel | atp500 |
| zyxel | atp500 firmware |
| zyxel | atp700 |
| zyxel | atp700 firmware |
| zyxel | atp800 |
| zyxel | atp800 firmware |
| zyxel | usg flex 100w |
| zyxel | usg flex 100w firmware |
| zyxel | usg flex 200 |
| zyxel | usg flex 200 firmware |
| zyxel | usg flex 500 |
| zyxel | usg flex 500 firmware |
| zyxel | usg flex 50w |
| zyxel | usg flex 50w firmware |
| zyxel | usg flex 700 |
| zyxel | usg flex 700 firmware |
| zyxel | usg20w-vpn |
| zyxel | usg20w-vpn firmware |
| zyxel | vpn100 |
| zyxel | vpn100 firmware |
| zyxel | vpn1000 |
| zyxel | vpn1000 firmware |
| zyxel | vpn300 |
| zyxel | vpn300 firmware |
| zyxel | vpn50 |
| zyxel | vpn50 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Zyxel USG FLEX 5.21 - OS Command Injection | 2022-06-03 |
References
- http://packetstormsecurity.com/files/167176/Zyxel-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/167182/Zyxel-Firewall-ZTP-Unauthenticated-Command-Injection.html
- http://packetstormsecurity.com/files/167372/Zyxel-USG-FLEX-5.21-Command-Injection.html
- http://packetstormsecurity.com/files/168202/Zyxel-Firewall-SUID-Binary-Privilege-Escalation.html
- https://www.zyxel.com/support/Zyxel-security-advisory-for-OS-command-injection-vulnerability-of-firewalls.shtml
- http://packetstormsecurity.com/files/167176/Zyxel-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/167182/Zyxel-Firewall-ZTP-Unauthenticated-Command-Injection.html
- http://packetstormsecurity.com/files/167372/Zyxel-USG-FLEX-5.21-Command-Injection.html
- http://packetstormsecurity.com/files/168202/Zyxel-Firewall-SUID-Binary-Privilege-Escalation.html
- https://www.zyxel.com/support/Zyxel-security-advisory-for-OS-command-injection-vulnerability-of-firewalls.shtml
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30525
→ the Explorer · watch your stack · NVD