CVE-2022-26531
published 2022-05-24CVE-2022-26531: Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series…
PriorityP353high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
5.80%
92.3th percentile
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | 4.32 – 5.21 | — |
| zyxel | atp100w_firmware | 4.32 – 5.21 | — |
| zyxel | atp200_firmware | 4.32 – 5.21 | — |
| zyxel | atp500_firmware | 4.32 – 5.21 | — |
| zyxel | atp700_firmware | 4.32 – 5.21 | — |
| zyxel | atp800_firmware | 4.32 – 5.21 | — |
| zyxel | atp_series_firmware | — | — |
| zyxel | nap203_firmware | <= 6.25\(abfa.7\) | — |
| zyxel | nap303_firmware | <= 6.25\(abex.7\) | — |
| zyxel | nap353_firmware | <= 6.25\(abey.7\) | — |
| zyxel | nsg100_firmware | — | — |
| zyxel | nsg100_firmware | >= 1.00 < 1.33 | 1.33 |
| zyxel | nsg300_firmware | — | — |
| zyxel | nsg300_firmware | >= 1.00 < 1.33 | 1.33 |
| zyxel | nsg50_firmware | — | — |
| zyxel | nsg50_firmware | >= 1.00 < 1.33 | 1.33 |
| zyxel | nsg_series_firmware | — | — |
| zyxel | nwa110ax_firmware | <= 6.30\(abtg.2\) | — |
| zyxel | nwa1123-ac-hd_firmware | <= 6.25\(abin.6\) | — |
| zyxel | nwa1123-ac-pro_firmware | <= 6.25\(abhd.7\) | — |
| zyxel | nwa1123acv3_firmware | <= 6.30\(abvt.2\) | — |
| zyxel | nwa1302-ac_firmware | <= 6.25\(abku.6\) | — |
| zyxel | nwa210ax_firmware | <= 6.30\(abtd.2\) | — |
| zyxel | nwa50ax_firmware | <= 6.25\(abyw.5\) | — |
| zyxel | nwa5123-ac-hd_firmware | <= 6.25\(abim.6\) | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Zyxel USG/ZyWALL buffer overflow (EUVD-2022-31088)
vuldb·2026-05-10·CVSS 7.8
CVE-2022-26531 [HIGH] Zyxel USG/ZyWALL buffer overflow (EUVD-2022-31088)
A vulnerability labeled as critical has been found in Zyxel USG and ZyWALL. This impacts an unknown function. The manipulation results in buffer overflow.
This vulnerability is identified as CVE-2022-26531. The attack is only possible with local access. There is not any exploit available.
GHSA
GHSA-rg7w-p5vw-jmcc: Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4
ghsa_unreviewed·2022-05-25
CVE-2022-26531 [HIGH] CWE-20 GHSA-rg7w-p5vw-jmcc: Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.
Red Hat
kernel: powerpc/memhotplug: Add add_pages override for PPC
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49666 [MEDIUM] kernel: powerpc/memhotplug: Add add_pages override for PPC
kernel: powerpc/memhotplug: Add add_pages override for PPC
In the Linux kernel, the following vulnerability has been resolved:
powerpc/memhotplug: Add add_pages override for PPC
With commit ffa0b64e3be5 ("powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit")
the kernel now validate the addr against high_memory value. This results
in the below BUG_ON with dax pfns.
[ 635.798741][T26531] kernel BUG at mm/page_alloc.c:5521!
1:mon> e
cpu 0x1: Vector: 700 (Program Check) at [c000000007287630]
pc: c00000000055ed48: free_pages.part.0+0x48/0x110
lr: c00000000053ca70: tlb_finish_mmu+0x80/0xd0
sp: c0000000072878d0
msr: 800000000282b033
current = 0xc00000000afabe00
paca = 0xc00000037ffff300 irqmask: 0x03 irq_happened: 0x05
pid = 26531, comm = 50-landscape-sy
kernel BUG at :5521!
Linux version
No detection rules found.
Checkpoint
30th May – Threat Intelligence Report
blogs_checkpoint·2022-05-30
CVE-2022-26833 30th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research reported how the Conti ransom group has taken cybercrime to a new, geopolitical level. They intervene in the internal politics of Costa Rica, the relationship between Costa Rica and the US, and basically moved the ransomware gangs to a new business stage of country extortion.
Check Point Harmony Endpoint and
Bugzilla
CVE-2022-49666 kernel: powerpc/memhotplug: Add add_pages override for PPC
bugzilla·2025-02-26·CVSS 3.5
CVE-2022-49666 [LOW] CVE-2022-49666 kernel: powerpc/memhotplug: Add add_pages override for PPC
CVE-2022-49666 kernel: powerpc/memhotplug: Add add_pages override for PPC
In the Linux kernel, the following vulnerability has been resolved:
powerpc/memhotplug: Add add_pages override for PPC
With commit ffa0b64e3be5 ("powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit")
the kernel now validate the addr against high_memory value. This results
in the below BUG_ON with dax pfns.
[ 635.798741][T26531] kernel BUG at mm/page_alloc.c:5521!
1:mon> e
cpu 0x1: Vector: 700 (Program Check) at [c000000007287630]
pc: c00000000055ed48: free_pages.part.0+0x48/0x110
lr: c00000000053ca70: tlb_finish_mmu+0x80/0xd0
sp: c0000000072878d0
msr: 800000000282b033
current = 0xc00000000afabe00
paca = 0xc00000037ffff300 irqmask: 0x03 irq_happened: 0x05
pid = 26531, comm = 50-landscape-sy
kernel BUG at :55
http://packetstormsecurity.com/files/167464/Zyxel-Buffer-Overflow-Format-String-Command-Injection.htmlhttp://packetstormsecurity.com/files/177036/Zyxel-zysh-Format-String-Proof-Of-Concept.htmlhttp://seclists.org/fulldisclosure/2022/Jun/15https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtmlhttp://packetstormsecurity.com/files/167464/Zyxel-Buffer-Overflow-Format-String-Command-Injection.htmlhttp://packetstormsecurity.com/files/177036/Zyxel-zysh-Format-String-Proof-Of-Concept.htmlhttp://seclists.org/fulldisclosure/2022/Jun/15https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml
2022-05-24
Published