V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2022-30525
CVE
Critical KEVConfirmedExploit available

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 …

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2022-01-01
Updated
2022-05-16
Description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Tags · CWE
KEVPre-auth
CWE-78
CAPEC-6
CAPEC-15
CAPEC-43
CAPEC-88
CAPEC-108
Affected products
Atp100_firmwareAtp100w_firmwareAtp200_firmwareAtp500_firmwareAtp700_firmwareAtp800_firmwareUsg20w-vpn_firmwareUsg_flex_100w_firmwareUsg_flex_200_firmwareUsg_flex_500_firmwareUsg_flex_50w_firmwareUsg_flex_700_firmwareVpn1000_firmwareVpn100_firmwareVpn300_firmwareVpn50_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-05-16
Added to KEV
2022-05-16
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.944 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2022-30525
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
50946
exploitdb · https://www.exploit-db.com/exploits/50946
Enterprise
Affected software
ProductVendorStatus
atp100_firmware*Exploited
atp100w_firmware*Exploited
atp200_firmware*Exploited
atp500_firmware*Exploited
atp700_firmware*Exploited
atp800_firmware*Exploited
usg20w-vpn_firmware*Exploited
usg_flex_100w_firmware*Exploited
usg_flex_200_firmware*Exploited
usg_flex_500_firmware*Exploited
usg_flex_50w_firmware*Exploited
usg_flex_700_firmware*Exploited
vpn1000_firmware*Exploited
vpn100_firmware*Exploited
vpn300_firmware*Exploited
vpn50_firmware*Exploited
Source databases
CVE
Related vulnerabilities