Executive brief
An OS command injection vulnerability in the CGI program of multiple Zyxel firewall series allows unauthenticated remote attackers to execute arbitrary OS commands by modifying specific files. The vulnerability affects USG FLEX, ATP, and VPN series devices running specific firmware versions.
Affected products
- Zyxel USG FLEX 100(W) firmware 5.00 through 5.21 Patch 1
- Zyxel USG FLEX 200 firmware 5.00 through 5.21 Patch 1
- Zyxel USG FLEX 500 firmware 5.00 through 5.21 Patch 1
- Zyxel USG FLEX 700 firmware 5.00 through 5.21 Patch 1
- Zyxel USG FLEX 50(W) firmware 5.10 through 5.21 Patch 1
- Zyxel USG20(W)-VPN firmware 5.10 through 5.21 Patch 1
- Zyxel ATP series firmware 5.10 through 5.21 Patch 1
- Zyxel VPN series firmware 4.60 through 5.21 Patch 1
Timeline
- 2022-05-12: disclosed: Initial discovery/reporting period based on advisory timing
- 2022-05-16: advisory: Zyxel security advisory published
- 2022-05-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-16: exploited: Confirmed exploited in the wild per CISA KEV entry