Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.

Project Subscriptions

Vendors Products
Atp100 Firmware Subscribe
Atp100w Subscribe
Atp100w Firmware Subscribe
Atp200 Firmware Subscribe
Atp500 Firmware Subscribe
Atp700 Firmware Subscribe
Atp800 Firmware Subscribe
Nap203 Firmware Subscribe
Nap303 Firmware Subscribe
Nap353 Firmware Subscribe
Nsg100 Firmware Subscribe
Nsg300 Firmware Subscribe
Nsg50 Firmware Subscribe
Nwa110ax Subscribe
Nwa110ax Firmware Subscribe
Nwa1123-ac-hd Subscribe
Nwa1123-ac-hd Firmware Subscribe
Nwa1123-ac-pro Subscribe
Nwa1123-ac-pro Firmware Subscribe
Nwa1123acv3 Subscribe
Nwa1123acv3 Firmware Subscribe
Nwa1302-ac Subscribe
Nwa1302-ac Firmware Subscribe
Nwa210ax Subscribe
Nwa210ax Firmware Subscribe
Nwa50ax Subscribe
Nwa50ax Firmware Subscribe
Nwa5123-ac-hd Subscribe
Nwa5123-ac-hd Firmware Subscribe
Nwa55axe Subscribe
Nwa55axe Firmware Subscribe
Nwa90ax Subscribe
Nwa90ax Firmware Subscribe
Nxc2500 Subscribe
Nxc2500 Firmware Subscribe
Nxc5500 Subscribe
Nxc5500 Firmware Subscribe
Usg200 Firmware Subscribe
Usg20 Firmware Subscribe
Usg210 Firmware Subscribe
Usg2200 Subscribe
Usg2200 Firmware Subscribe
Usg300 Firmware Subscribe
Usg310 Firmware Subscribe
Usg 110 Subscribe
Usg 1100 Subscribe
Usg 1100 Firmware Subscribe
Usg 110 Firmware Subscribe
Usg 1900 Subscribe
Usg 1900 Firmware Subscribe
Usg 20w Subscribe
Usg 20w-vpn Subscribe
Usg 20w-vpn Firmware Subscribe
Usg 20w Firmware Subscribe
Usg 2200-vpn Subscribe
Usg 2200-vpn Firmware Subscribe
Usg 310 Subscribe
Usg 310 Firmware Subscribe
Usg 40 Firmware Subscribe
Usg 40w Subscribe
Usg 40w Firmware Subscribe
Usg 60 Firmware Subscribe
Usg 60w Subscribe
Usg 60w Firmware Subscribe
Usg Flex 100 Subscribe
Usg Flex 100 Firmware Subscribe
Usg Flex 100w Subscribe
Usg Flex 100w Firmware Subscribe
Usg Flex 200 Subscribe
Usg Flex 200 Firmware Subscribe
Usg Flex 500 Subscribe
Usg Flex 500 Firmware Subscribe
Usg Flex 700 Subscribe
Usg Flex 700 Firmware Subscribe
Vpn1000 Subscribe
Vpn1000 Firmware Subscribe
Vpn100 Firmware Subscribe
Vpn300 Firmware Subscribe
Vpn50 Firmware Subscribe
Wac500 Firmware Subscribe
Wac500h Subscribe
Wac500h Firmware Subscribe
Wac5302d-s Subscribe
Wac5302d-s Firmware Subscribe
Wac5302d-sv2 Subscribe
Wac5302d-sv2 Firmware Subscribe
Wac6103d-i Subscribe
Wac6103d-i Firmware Subscribe
Wac6303d-s Subscribe
Wac6303d-s Firmware Subscribe
Wac6502d-e Subscribe
Wac6502d-e Firmware Subscribe
Wac6502d-s Subscribe
Wac6502d-s Firmware Subscribe
Wac6503d-s Subscribe
Wac6503d-s Firmware Subscribe
Wac6552d-s Subscribe
Wac6552d-s Firmware Subscribe
Wac6553d-s Subscribe
Wac6553d-s Firmware Subscribe
Wax510d Subscribe
Wax510d Firmware Subscribe
Wax610d Subscribe
Wax610d Firmware Subscribe
Wax630s Subscribe
Wax630s Firmware Subscribe
Wax650s Subscribe
Wax650s Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-31088 Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00989}

epss

{'score': 0.0073}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-03T05:03:33.155Z

Reserved: 2022-03-07T00:00:00

Link: CVE-2022-26531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-24T06:15:09.297

Modified: 2024-11-21T06:54:07.470

Link: CVE-2022-26531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses