7.8

CVE-2022-26532

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.

Data is provided by the National Vulnerability Database (NVD)
ZyxelVpn100 Firmware Version >= 4.30 <= 5.21
   ZyxelVpn100 Version-
ZyxelVpn1000 Firmware Version >= 4.30 <= 5.21
   ZyxelVpn1000 Version-
ZyxelVpn300 Firmware Version >= 4.30 <= 5.21
   ZyxelVpn300 Version-
ZyxelVpn50 Firmware Version >= 4.30 <= 5.21
   ZyxelVpn50 Version-
ZyxelAtp100 Firmware Version >= 4.32 <= 5.21
   ZyxelAtp100 Version-
ZyxelAtp100w Firmware Version >= 4.32 <= 5.21
   ZyxelAtp100w Version-
ZyxelAtp200 Firmware Version >= 4.32 <= 5.21
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version >= 4.32 <= 5.21
   ZyxelAtp500 Version-
ZyxelAtp700 Firmware Version >= 4.32 <= 5.21
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version >= 4.32 <= 5.21
   ZyxelAtp800 Version-
ZyxelUsg 110 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 110 Version-
ZyxelUsg 1100 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 1100 Version-
ZyxelUsg 1900 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 1900 Version-
ZyxelUsg 20w Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 20w Version-
ZyxelUsg 20w-vpn Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 20w-vpn Version-
ZyxelUsg 2200-vpn Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 2200-vpn Version-
ZyxelUsg 310 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 310 Version-
ZyxelUsg 40 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 40 Version-
ZyxelUsg 40w Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 40w Version-
ZyxelUsg 60 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 60 Version-
ZyxelUsg 60w Firmware Version >= 4.09 <= 4.71
   ZyxelUsg 60w Version-
ZyxelUsg Flex 100 Firmware Version >= 4.50 <= 5.21
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100w Firmware Version >= 4.50 <= 5.21
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 200 Firmware Version >= 4.50 <= 5.21
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 500 Firmware Version >= 4.50 <= 5.21
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 700 Firmware Version >= 4.50 <= 5.21
   ZyxelUsg Flex 700 Version-
ZyxelUsg200 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg200 Version-
ZyxelUsg20 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg20 Version-
ZyxelUsg210 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg210 Version-
ZyxelUsg2200 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg2200 Version-
ZyxelUsg300 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg300 Version-
ZyxelUsg310 Firmware Version >= 4.09 <= 4.71
   ZyxelUsg310 Version-
ZyxelNsg300 Firmware Version >= 1.00 < 1.33
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Update-
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Updatepatch1
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Updatepatch2
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Updatepatch3
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Updatepatch4
   ZyxelNsg300 Version-
ZyxelNsg100 Firmware Version >= 1.00 < 1.33
   ZyxelNsg100 Version-
ZyxelNsg100 Firmware Version1.33 Update-
   ZyxelNsg100 Version-
ZyxelNsg100 Firmware Version1.33 Updatepatch1
   ZyxelNsg100 Version-
ZyxelNsg100 Firmware Version1.33 Updatepatch2
   ZyxelNsg100 Version-
ZyxelNsg100 Firmware Version1.33 Updatepatch3
   ZyxelNsg100 Version-
ZyxelNsg100 Firmware Version1.33 Updatepatch4
   ZyxelNsg100 Version-
ZyxelNsg50 Firmware Version >= 1.00 < 1.33
   ZyxelNsg50 Version-
ZyxelNsg50 Firmware Version1.33 Update-
   ZyxelNsg50 Version-
ZyxelNsg50 Firmware Version1.33 Updatepatch1
   ZyxelNsg50 Version-
ZyxelNsg50 Firmware Version1.33 Updatepatch2
   ZyxelNsg50 Version-
ZyxelNsg50 Firmware Version1.33 Updatepatch3
   ZyxelNsg50 Version-
ZyxelNsg50 Firmware Version1.33 Updatepatch4
   ZyxelNsg50 Version-
ZyxelNxc2500 Firmware Version <= 6.10\(aaig.3\)
   ZyxelNxc2500 Version-
ZyxelNxc5500 Firmware Version <= 6.10\(aaos.3\)
   ZyxelNxc5500 Version-
ZyxelNap203 Firmware Version <= 6.25\(abfa.7\)
   ZyxelNap203 Version-
ZyxelNap303 Firmware Version <= 6.25\(abex.7\)
   ZyxelNap303 Version-
ZyxelNap353 Firmware Version <= 6.25\(abey.7\)
   ZyxelNap353 Version-
ZyxelNwa50ax Firmware Version <= 6.25\(abyw.5\)
   ZyxelNwa50ax Version-
ZyxelNwa55axe Firmware Version <= 6.25\(abzl.5\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version <= 6.27\(accv.2\)
   ZyxelNwa90ax Version-
ZyxelNwa110ax Firmware Version <= 6.30\(abtg.2\)
   ZyxelNwa110ax Version-
ZyxelNwa210ax Firmware Version <= 6.30\(abtd.2\)
   ZyxelNwa210ax Version-
ZyxelNwa1123-ac-hd Firmware Version <= 6.25\(abin.6\)
   ZyxelNwa1123-ac-hd Version-
ZyxelNwa1123-ac-pro Firmware Version <= 6.25\(abhd.7\)
   ZyxelNwa1123-ac-pro Version-
ZyxelNwa1123acv3 Firmware Version <= 6.30\(abvt.2\)
   ZyxelNwa1123acv3 Version-
ZyxelNwa1302-ac Firmware Version <= 6.25\(abku.6\)
   ZyxelNwa1302-ac Version-
ZyxelNwa5123-ac-hd Firmware Version <= 6.25\(abim.6\)
   ZyxelNwa5123-ac-hd Version-
ZyxelWac500h Firmware Version <= 6.30\(abwa.2\)
   ZyxelWac500h Version-
ZyxelWac500 Firmware Version <= 6.30\(abvs.2\)
   ZyxelWac500 Version-
ZyxelWac5302d-s Firmware Version <= 6.10\(abfh.10\)
   ZyxelWac5302d-s Version-
ZyxelWac5302d-sv2 Firmware Version <= 6.25\(abvz.6\)
   ZyxelWac5302d-sv2 Version-
ZyxelWac6103d-i Firmware Version <= 6.25\(aaxh.7\)
   ZyxelWac6103d-i Version-
ZyxelWac6303d-s Firmware Version <= 6.25\(abgl.6\)
   ZyxelWac6303d-s Version-
ZyxelWac6502d-e Firmware Version <= 6.25\(aasd.7\)
   ZyxelWac6502d-e Version-
ZyxelWac6502d-s Firmware Version <= 6.25\(aase.7\)
   ZyxelWac6502d-s Version-
ZyxelWac6503d-s Firmware Version <= 6.25\(aasf.7\)
   ZyxelWac6503d-s Version-
ZyxelWac6553d-s Firmware Version <= 6.25\(aasg.7\)
   ZyxelWac6553d-s Version-
ZyxelWac6552d-s Firmware Version <= 6.25\(abio.7\)
   ZyxelWac6552d-s Version-
ZyxelWax510d Firmware Version <= 6.30\(abtf.2\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version <= 6.30\(abte.2\)
   ZyxelWax610d Version-
ZyxelWax630s Firmware Version <= 6.30\(abzd.2\)
   ZyxelWax630s Version-
ZyxelWax650s Firmware Version <= 6.30\(abrm.2\)
   ZyxelWax650s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.67% 0.815
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
security@zyxel.com.tw 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.