8

CVE-2022-26413

A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.

Data is provided by the National Vulnerability Database (NVD)
ZyxelVmg3312-t20a Firmware Version5.30(abfx.5)c0
   ZyxelVmg3312-t20a Version-
ZyxelEmg3525-t50b Firmware SwEditionamerica Version < 5.50\(abpm.6\)c0
   ZyxelEmg3525-t50b Version-
ZyxelEmg3525-t50b Firmware SwEditionemea Version < 5.50\(abpm.6\)c0
   ZyxelEmg3525-t50b Version-
ZyxelEmg5523-t50b Firmware SwEditionamerica Version < 5.50\(abpm.6\)c0
   ZyxelEmg5523-t50b Version-
ZyxelEmg5523-t50b Firmware SwEditionemea Version < 5.50\(abpm.6\)c0
   ZyxelEmg5523-t50b Version-
ZyxelEmg5723-t50k Firmware Version < 5.50\(abom.7\)c0
   ZyxelEmg5723-t50k Version-
ZyxelEmg6726-b10a Firmware Version < 5.13\(abnp.7\)c0
   ZyxelEmg6726-b10a Version-
ZyxelVmg1312-t20b Firmware Version < 5.50\(absb.5\)c0
   ZyxelVmg1312-t20b Version-
ZyxelVmg3625-t50b Firmware Version < 5.50\(abpm.6\)c0
   ZyxelVmg3625-t50b Version-
ZyxelVmg3927-b50a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelVmg3927-b50a Version-
ZyxelVmg3927-b50b Firmware Version < 5.13\(ably.7\)c0
   ZyxelVmg3927-b50b Version-
ZyxelVmg3927-b60a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelVmg3927-b60a Version-
ZyxelVmg3927-t50k Firmware Version < 5.50\(abom.7\)c0
   ZyxelVmg3927-t50k Version-
ZyxelVmg4927-b50a Firmware Version < 5.13\(ably.7\)c0
   ZyxelVmg4927-b50a Version-
ZyxelVmg8623-t50b Firmware Version < 5.50\(abpm.6\)c0
   ZyxelVmg8623-t50b Version-
ZyxelVmg8825-b50a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelVmg8825-b50a Version-
ZyxelVmg8825-b50b Firmware Version < 5.17\(abny.7\)c0
   ZyxelVmg8825-b50b Version-
ZyxelVmg8825-t50k Firmware Version < 5.50\(abom.7\)c0
   ZyxelVmg8825-t50k Version-
ZyxelVmg8825-b60a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelVmg8825-b60a Version-
ZyxelVmg8825-b60b Firmware Version < 5.17\(abny.7\)c0
   ZyxelVmg8825-b60b Version-
ZyxelXmg3927-b50a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelXmg3927-b50a Version-
ZyxelXmg8825-b50a Firmware Version < 5.17\(abmt.6\)c0
   ZyxelXmg8825-b50a Version-
ZyxelDx5401-b0 Firmware Version < 5.17\(abyo.1\)c0
   ZyxelDx5401-b0 Version-
ZyxelEx3510-b0 Firmware Version < 5.17\(abup.4\)c1
   ZyxelEx3510-b0 Version-
ZyxelEx5401-b0 Firmware Version < 5.17\(abyo.1\)c0
   ZyxelEx5401-b0 Version-
ZyxelEx5501-b0 Firmware Version < 5.17\(abry.2\)c0
   ZyxelEx5501-b0 Version-
ZyxelAx7501-b0 Firmware Version < 5.17\(abpc.1\)c0
   ZyxelAx7501-b0 Version-
ZyxelEp240p Firmware Version < 5.40\(abh.0\)c0
   ZyxelEp240p Version-
ZyxelPm7300-t0 Firmware Version < 5.42\(acbc.1\)c0
   ZyxelPm7300-t0 Version-
ZyxelPmg5317-t20b Firmware Version < 5.40\(abki.4\)c0
   ZyxelPmg5317-t20b Version-
ZyxelPmg5617ga Firmware Version < 5.40\(abna.2\)c0
   ZyxelPmg5617ga Version-
ZyxelPmg5617-t20b2 Firmware Version < 5.41\(acbb.1\)c0
   ZyxelPmg5617-t20b2 Version-
ZyxelPmg5622ga Firmware Version < 5.40\(abnb.2\)c0
   ZyxelPmg5622ga Version-
ZyxelPx7501-b0 Firmware Version < 5.17\(abpc.1\)c0
   ZyxelPx7501-b0 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.63% 0.692
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.7 5.1 10
AV:A/AC:L/Au:S/C:C/I:C/A:C
security@zyxel.com.tw 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.