Lucene search

K
nvd[email protected]NVD:CVE-2022-30525
HistoryMay 12, 2022 - 2:15 p.m.

CVE-2022-30525

2022-05-1214:15:07
CWE-78
web.nvd.nist.gov
1

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Affected configurations

NVD
Node
zyxelusg_flex_100w_firmwareRange5.005.30
AND
zyxelusg_flex_100wMatch-
Node
zyxelusg_flex_200_firmwareRange5.005.30
AND
zyxelusg_flex_200Match-
Node
zyxelusg_flex_500_firmwareRange5.005.30
AND
zyxelusg_flex_500Match-
Node
zyxelusg_flex_700_firmwareRange5.005.30
AND
zyxelusg_flex_700Match-
Node
zyxelvpn100_firmwareRange4.605.30
AND
zyxelvpn100Match-
Node
zyxelvpn1000_firmwareRange4.605.30
AND
zyxelvpn1000Match-
Node
zyxelvpn300_firmwareRange4.605.30
AND
zyxelvpn300Match-
Node
zyxelvpn50_firmwareRange4.605.30
AND
zyxelvpn50Match-
Node
zyxelatp100_firmwareRange5.105.30
AND
zyxelatp100Match-
Node
zyxelatp100w_firmwareRange5.105.30
AND
zyxelatp100wMatch-
Node
zyxelatp200_firmwareRange5.105.30
AND
zyxelatp200Match-
Node
zyxelatp500_firmwareRange5.105.30
AND
zyxelatp500Match-
Node
zyxelatp700_firmwareRange5.105.30
AND
zyxelatp700Match-
Node
zyxelatp800_firmwareRange5.105.30
AND
zyxelatp800Match-
Node
zyxelusg_flex_50w_firmwareRange5.105.30
AND
zyxelusg_flex_50wMatch-
Node
zyxelusg20w-vpn_firmwareRange5.105.30
AND
zyxelusg20w-vpnMatch-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%