⚠ Actively exploited
Added to CISA KEV on 2022-05-16. Federal agencies required to patch by 2022-06-06. Required action: Apply updates per vendor instructions..

CVE-2022-30525

CWE-78OS Command Injection12 documents10 sources
Severity
9.8CRITICAL
EPSS
94.4%
top < 0.01%
CISA KEV
KEV
Added 2022-05-16
Due 2022-06-06
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 12
KEV addedMay 16
KEV dueJun 6
Latest updateJun 22
CISA Required Action: Apply updates per vendor instructions.

Description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versio

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages24 packages

NVDzyxel/usg_flex_200_firmware5.005.30
NVDzyxel/usg_flex_50w_firmware5.105.30
NVDzyxel/usg_flex_700_firmware5.005.30
NVDzyxel/usg_flex_100w_firmware5.005.30
NVDzyxel/usg_flex_500_firmware5.005.30

🔴Vulnerability Details

3
GHSA
GHSA-987m-9prq-3p7m: A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 52022-05-13
CVEList
CVE-2022-30525: A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 52022-05-12
VulnCheck
Zyxel Multiple Firewalls OS Command Injection Vulnerability2022

💥Exploits & PoCs

5
Exploit-DB
Zyxel USG FLEX 5.21 - OS Command Injection2022-06-03
Metasploit
Zyxel Firewall ZTP Unauthenticated Command Injection
Nuclei
Unauthenticated ZyXEL USG ZTP - Detect
Nuclei
Zyxel Firewall - OS Command Injection
Metasploit
Zyxel Firewall SUID Binary Privilege Escalation

🔍Detection Rules

1
Suricata
ET EXPLOIT [Rapid7] Zyxel ZTP setWanPortSt mtu Parameter Exploit Attempt (CVE-2022-30525)2022-05-16

📋Vendor Advisories

1
CISA
Zyxel Multiple Firewalls OS Command Injection Vulnerability2022-05-16

🕵️Threat Intelligence

1
Unit42
IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits2023-06-22
CVE-2022-30525 (CRITICAL CVSS 9.8) | A OS command injection vulnerabilit | cvebase.io