CVE-2025-8078
published 2025-10-21CVE-2025-8078: A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from…
PriorityP353high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.48%
71.1th percentile
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on the affected device by passing a crafted string as an argument to a CLI command.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20_vpn_series_firmware | — | — |
| zyxel | usg_flex_50_series_firmware | — | — |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | zld | >= 4.16 < 5.41 | 5.41 |
| zyxel | zld | >= 4.32 < 5.41 | 5.41 |
| zyxel | zld | >= 4.50 < 5.41 | 5.41 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Zyxel ATP Authenticated Remote Code Execution (CVE-2025-8078)
suricata·2025-12-02·CVSS 7.2
CVE-2025-8078 [HIGH] ET WEB_SPECIFIC_APPS Zyxel ATP Authenticated Remote Code Execution (CVE-2025-8078)
ET WEB_SPECIFIC_APPS Zyxel ATP Authenticated Remote Code Execution (CVE-2025-8078)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Zyxel ATP Authenticated Remote Code Execution (CVE-2025-8078)"; flow:established,to_server; http.uri; content:"/cgi-bin/zysh-cgi"; fast_pattern; http.request_body; content:"cmd|3d|"; pcre:"/^[^&]*?(?:[\x3b\x24\x60\x7c]|\x25(?:3[bB]|24|60|7[cC]))/R"; http.method; content:"POST"; reference:url,rainpwn.blog/blog/cve-2025-8078/; reference:cve,2025-8078; classtype:web-application-attack; sid:2065977; rev:1; metadata:affected_product Zyxel, attack_target Server, tls_state TLSDecrypt, created_at 2025_12_02, cve CVE_2025_8078, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit,
No public exploits indexed.
No writeups or analysis indexed.
2025-10-21
Published