CVE-2022-30525
Description
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
StableCommon Consequences
Applicable Platforms
Zyxel USG FLEX 5.21 - OS Command Injection
Zyxel USG FLEX 5.21 - OS Command Injection
View Exploit Code →Usg Flex 700 Firmware by Zyxel
cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*
Vpn50 Firmware by Zyxel
cpe:2.3:o:zyxel:vpn50_firmware:*:*:*:*:*:*:*:*
Atp500 Firmware by Zyxel
cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*
Usg Flex 500 Firmware by Zyxel
cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*
Vpn300 Firmware by Zyxel
cpe:2.3:o:zyxel:vpn300_firmware:*:*:*:*:*:*:*:*
Atp100W Firmware by Zyxel
cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*
Vpn100 Firmware by Zyxel
cpe:2.3:o:zyxel:vpn100_firmware:*:*:*:*:*:*:*:*
Atp100 Firmware by Zyxel
cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*
Usg Flex 200 Firmware by Zyxel
cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*
Atp800 Firmware by Zyxel
cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:*
Usg Flex 100W Firmware by Zyxel
cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*
Usg20W-Vpn Firmware by Zyxel
cpe:2.3:o:zyxel:usg20w-vpn_firmware:*:*:*:*:*:*:*:*
Atp200 Firmware by Zyxel
cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:*
Atp700 Firmware by Zyxel
cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*
Usg Flex 50W Firmware by Zyxel
cpe:2.3:o:zyxel:usg_flex_50w_firmware:*:*:*:*:*:*:*:*
Vpn1000 Firmware by Zyxel
cpe:2.3:o:zyxel:vpn1000_firmware:*:*:*:*:*:*:*:*