CVE-2022-0342
published 2022-03-28CVE-2022-0342: An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
84.42%
99.7th percentile
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | 4.32 – 5.20 | — |
| zyxel | atp100w_firmware | 4.32 – 5.20 | — |
| zyxel | atp200_firmware | 4.32 – 5.20 | — |
| zyxel | atp500_firmware | 4.32 – 5.20 | — |
| zyxel | atp700_firmware | 4.32 – 5.20 | — |
| zyxel | atp800_firmware | 4.32 – 5.20 | — |
| zyxel | atp_series_firmware | — | — |
| zyxel | nsg300_firmware | — | — |
| zyxel | nsg300_firmware | >= 1.20 < 1.33 | 1.33 |
| zyxel | nsg_series_firmware | — | — |
| zyxel | usg40_firmware | >= 4.20 < 4.71 | 4.71 |
| zyxel | usg40w_firmware | >= 4.20 < 4.71 | 4.71 |
| zyxel | usg60_firmware | >= 4.20 < 4.71 | 4.71 |
| zyxel | usg60w_firmware | >= 4.20 < 4.71 | 4.71 |
| zyxel | usg_flex_100_firmware | 4.50 – 5.20 | — |
| zyxel | usg_flex_100w_firmware | 4.50 – 5.20 | — |
| zyxel | usg_flex_200_firmware | 4.50 – 5.20 | — |
| zyxel | usg_flex_500_firmware | 4.50 – 5.20 | — |
| zyxel | usg_flex_700_firmware | 4.50 – 5.20 | — |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | usg_zywall_series_firmware | — | — |
| zyxel | vpn1000_firmware | >= 4.30 < 5.21 | 5.21 |
| zyxel | vpn100_firmware | >= 4.30 < 5.21 | 5.21 |
| zyxel | vpn300_firmware | >= 4.30 < 5.21 | 5.21 |
| zyxel | vpn50_firmware | >= 4.30 < 5.21 | 5.21 |
Detection & IOCsextracted from sources · hover to see the quote
path/cgi-bin/export-cgi
filenamestartup-config.conf
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel USG/Zywall Authentication Bypass Attempt (CVE-2022-0342)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/export-cgi?category=config&arg0=startup-config.conf"; fast_pattern; reference:url,github.com/projectdiscovery/nuclei-templates/blob/5a70e30cfc52ba07a24c23a250c985f926cff8e4/http/cves/2022/CVE-2022-0342.yaml; reference:cve,2022-0342; classtype:attempted-admin; sid:2056775; rev:2; metadata:affected_product Zyxel, created_at 2024_10_22, cve CVE_2022_0342, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
- →HTTP GET to /cgi-bin/export-cgi?category=config&arg0=startup-config.conf unauthenticated — successful exploitation returns HTTP 200 with body containing 'interface-name' and 'saved at', and Content-Type header containing 'text/zyxel' and 'attachment; filename='
- →FOFA fingerprinting queries to identify exposed Zyxel devices: search for body containing '/2FA-access.cgi' AND 'zyxel zyxel_style1' (case-insensitive variant also uses '/2fa-access.cgi')
- →The vulnerability resides in the CGI program; the exploit is a single unauthenticated GET request — no credentials or prior session required (PR:N, UI:N per CVSS)
- →Classify exploit traffic under MITRE ATT&CK T1190 (Exploit Public-Facing Application) / TA0001 (Initial Access) for alert triage
- ·Affected firmware ranges are broad; ensure version-scoped detection — USG/ZyWALL 4.20–4.70, USG FLEX 4.50–5.20, ATP 4.32–5.20, VPN 4.30–5.20, NSG V1.20–V1.33 Patch 4 ↗
- ·EPSS score of 0.92364 (99.7th percentile) indicates very high probability of exploitation in the wild; treat as high-priority for detection and patching
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5g3j-g6gx-xfcg: An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4
ghsa_unreviewed·2022-03-29
CVE-2022-0342 [CRITICAL] CWE-287 GHSA-5g3j-g6gx-xfcg: An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
VulnCheck
Zyxel usg40_firmware Improper Authentication
vulncheck·2022·CVSS 9.8
CVE-2022-0342 [CRITICAL] Zyxel usg40_firmware Improper Authentication
Zyxel usg40_firmware Improper Authentication
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Affected: Zyxel usg40_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.vulncheck.com/v3/index/vulncheck-canaries?cve=CVE-2022-0342&date=2025-10-17; https:
Suricata
ET WEB_SPECIFIC_APPS Zyxel USG/Zywall Authentication Bypass Attempt (CVE-2022-0342)
suricata·2024-10-22·CVSS 9.8
CVE-2022-0342 [CRITICAL] ET WEB_SPECIFIC_APPS Zyxel USG/Zywall Authentication Bypass Attempt (CVE-2022-0342)
ET WEB_SPECIFIC_APPS Zyxel USG/Zywall Authentication Bypass Attempt (CVE-2022-0342)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel USG/Zywall Authentication Bypass Attempt (CVE-2022-0342)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/export-cgi?category=config&arg0=startup-config.conf"; fast_pattern; reference:url,github.com/projectdiscovery/nuclei-templates/blob/5a70e30cfc52ba07a24c23a250c985f926cff8e4/http/cves/2022/CVE-2022-0342.yaml; reference:cve,2022-0342; classtype:attempted-admin; sid:2056775; rev:2; metadata:affected_product Zyxel, created_at 2024_10_22, cve CVE_2022_0342, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nex
Nuclei
Zyxel - Authentication Bypass
nuclei·CVSS 9.8
CVE-2022-0342 [CRITICAL] Zyxel - Authentication Bypass
Zyxel - Authentication Bypass
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Template:
id: CVE-2022-0342
info:
name: Zyxel - Authentication Bypass
author: SleepingBag945,Powerexploit
severity: critical
description: |
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP ser
2022-03-28
Published
Exploited in the wild