7.8
CVE-2022-26532
- EPSS 1.67%
- Published 24.05.2022 06:15:09
- Last modified 21.11.2024 06:54:07
- Source security@zyxel.com.tw
- Teams watchlist Login
- Open Login
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.
Data is provided by the National Vulnerability Database (NVD)
Zyxel ≫ Vpn100 Firmware Version >= 4.30 <= 5.21
Zyxel ≫ Vpn1000 Firmware Version >= 4.30 <= 5.21
Zyxel ≫ Vpn300 Firmware Version >= 4.30 <= 5.21
Zyxel ≫ Vpn50 Firmware Version >= 4.30 <= 5.21
Zyxel ≫ Atp100 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp100w Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp200 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp500 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp700 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp800 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Usg 110 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 1100 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 1900 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 20w Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 20w-vpn Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 2200-vpn Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 310 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 40 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 40w Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 60 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg 60w Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg Flex 100 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 100w Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 200 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 500 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 700 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg200 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg20 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg210 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg2200 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg300 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Usg310 Firmware Version >= 4.09 <= 4.71
Zyxel ≫ Nsg300 Firmware Version >= 1.00 < 1.33
Zyxel ≫ Nsg300 Firmware Version1.33 Update-
Zyxel ≫ Nsg300 Firmware Version1.33 Updatepatch1
Zyxel ≫ Nsg300 Firmware Version1.33 Updatepatch2
Zyxel ≫ Nsg300 Firmware Version1.33 Updatepatch3
Zyxel ≫ Nsg300 Firmware Version1.33 Updatepatch4
Zyxel ≫ Nsg100 Firmware Version >= 1.00 < 1.33
Zyxel ≫ Nsg100 Firmware Version1.33 Update-
Zyxel ≫ Nsg100 Firmware Version1.33 Updatepatch1
Zyxel ≫ Nsg100 Firmware Version1.33 Updatepatch2
Zyxel ≫ Nsg100 Firmware Version1.33 Updatepatch3
Zyxel ≫ Nsg100 Firmware Version1.33 Updatepatch4
Zyxel ≫ Nsg50 Firmware Version >= 1.00 < 1.33
Zyxel ≫ Nsg50 Firmware Version1.33 Update-
Zyxel ≫ Nsg50 Firmware Version1.33 Updatepatch1
Zyxel ≫ Nsg50 Firmware Version1.33 Updatepatch2
Zyxel ≫ Nsg50 Firmware Version1.33 Updatepatch3
Zyxel ≫ Nsg50 Firmware Version1.33 Updatepatch4
Zyxel ≫ Nxc2500 Firmware Version <= 6.10\(aaig.3\)
Zyxel ≫ Nxc5500 Firmware Version <= 6.10\(aaos.3\)
Zyxel ≫ Nap203 Firmware Version <= 6.25\(abfa.7\)
Zyxel ≫ Nap303 Firmware Version <= 6.25\(abex.7\)
Zyxel ≫ Nap353 Firmware Version <= 6.25\(abey.7\)
Zyxel ≫ Nwa50ax Firmware Version <= 6.25\(abyw.5\)
Zyxel ≫ Nwa55axe Firmware Version <= 6.25\(abzl.5\)
Zyxel ≫ Nwa90ax Firmware Version <= 6.27\(accv.2\)
Zyxel ≫ Nwa110ax Firmware Version <= 6.30\(abtg.2\)
Zyxel ≫ Nwa210ax Firmware Version <= 6.30\(abtd.2\)
Zyxel ≫ Nwa1123-ac-hd Firmware Version <= 6.25\(abin.6\)
Zyxel ≫ Nwa1123-ac-pro Firmware Version <= 6.25\(abhd.7\)
Zyxel ≫ Nwa1123acv3 Firmware Version <= 6.30\(abvt.2\)
Zyxel ≫ Nwa1302-ac Firmware Version <= 6.25\(abku.6\)
Zyxel ≫ Nwa5123-ac-hd Firmware Version <= 6.25\(abim.6\)
Zyxel ≫ Wac500h Firmware Version <= 6.30\(abwa.2\)
Zyxel ≫ Wac500 Firmware Version <= 6.30\(abvs.2\)
Zyxel ≫ Wac5302d-s Firmware Version <= 6.10\(abfh.10\)
Zyxel ≫ Wac5302d-sv2 Firmware Version <= 6.25\(abvz.6\)
Zyxel ≫ Wac6103d-i Firmware Version <= 6.25\(aaxh.7\)
Zyxel ≫ Wac6303d-s Firmware Version <= 6.25\(abgl.6\)
Zyxel ≫ Wac6502d-e Firmware Version <= 6.25\(aasd.7\)
Zyxel ≫ Wac6502d-s Firmware Version <= 6.25\(aase.7\)
Zyxel ≫ Wac6503d-s Firmware Version <= 6.25\(aasf.7\)
Zyxel ≫ Wac6553d-s Firmware Version <= 6.25\(aasg.7\)
Zyxel ≫ Wac6552d-s Firmware Version <= 6.25\(abio.7\)
Zyxel ≫ Wax510d Firmware Version <= 6.30\(abtf.2\)
Zyxel ≫ Wax610d Firmware Version <= 6.30\(abte.2\)
Zyxel ≫ Wax630s Firmware Version <= 6.30\(abzd.2\)
Zyxel ≫ Wax650s Firmware Version <= 6.30\(abrm.2\)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.67% | 0.815 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
security@zyxel.com.tw | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.