Back to Labs
Security Advisory

CVE-2022-30525

About

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Weakness (CWE):CWE-78

Rainforest analyst review

A CGI program in Zyxel's firewall firmware passes attacker-influenced input into an OS command without proper sanitization. An unauthenticated attacker sends a crafted request to the device's web interface, writes to specific files, and from there executes commands on the underlying system. Because the vulnerable handler is reachable before login, exploitation is a direct, single-step path to code execution as the device runs it, no credentials and no user interaction required.

The affected models are USG FLEX, ATP, and VPN-series firewalls and VPN concentrators, appliances that sit at the network perimeter by definition and terminate remote access for the organizations behind them. Compromising one hands an attacker a position to pivot inward, intercept traffic, or stage further intrusion, which is why perimeter security gear is such a prized target and why this landed on CISA's KEV list with active exploitation reported shortly after disclosure. Apply Zyxel's ZLD 5.30 firmware. Beyond patching, restrict WAN-side access to the management interface, and hunt for unexpected file changes or new accounts, since an exposed device may already have been reached.

References

Related CVEs

Frequently asked questions

What is CVE-2022-30525?

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, AT…

How severe is CVE-2022-30525?

CVE-2022-30525 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2022-30525 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2022-30525?

Public advisories list the following as affected: atp100, atp100 firmware, atp100w, atp100w firmware, atp200, atp200 firmware, +26. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2022-30525?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email