Description
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.
Published: 2022-05-24
Score: 7.8 High
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-31089 A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.
History

No history.

Subscriptions

Zyxel Atp100 Atp100 Firmware Atp100w Atp100w Firmware Atp200 Atp200 Firmware Atp500 Atp500 Firmware Atp700 Atp700 Firmware Atp800 Atp800 Firmware Nap203 Nap203 Firmware Nap303 Nap303 Firmware Nap353 Nap353 Firmware Nsg100 Nsg100 Firmware Nsg300 Nsg300 Firmware Nsg50 Nsg50 Firmware Nwa110ax Nwa110ax Firmware Nwa1123-ac-hd Nwa1123-ac-hd Firmware Nwa1123-ac-pro Nwa1123-ac-pro Firmware Nwa1123acv3 Nwa1123acv3 Firmware Nwa1302-ac Nwa1302-ac Firmware Nwa210ax Nwa210ax Firmware Nwa50ax Nwa50ax Firmware Nwa5123-ac-hd Nwa5123-ac-hd Firmware Nwa55axe Nwa55axe Firmware Nwa90ax Nwa90ax Firmware Nxc2500 Nxc2500 Firmware Nxc5500 Nxc5500 Firmware Usg20 Usg200 Usg200 Firmware Usg20 Firmware Usg210 Usg210 Firmware Usg2200 Usg2200 Firmware Usg300 Usg300 Firmware Usg310 Usg310 Firmware Usg 110 Usg 1100 Usg 1100 Firmware Usg 110 Firmware Usg 1900 Usg 1900 Firmware Usg 20w Usg 20w-vpn Usg 20w-vpn Firmware Usg 20w Firmware Usg 2200-vpn Usg 2200-vpn Firmware Usg 310 Usg 310 Firmware Usg 40 Usg 40 Firmware Usg 40w Usg 40w Firmware Usg 60 Usg 60 Firmware Usg 60w Usg 60w Firmware Usg Flex 100 Usg Flex 100 Firmware Usg Flex 100w Usg Flex 100w Firmware Usg Flex 200 Usg Flex 200 Firmware Usg Flex 500 Usg Flex 500 Firmware Usg Flex 700 Usg Flex 700 Firmware Vpn100 Vpn1000 Vpn1000 Firmware Vpn100 Firmware Vpn300 Vpn300 Firmware Vpn50 Vpn50 Firmware Wac500 Wac500 Firmware Wac500h Wac500h Firmware Wac5302d-s Wac5302d-s Firmware Wac5302d-sv2 Wac5302d-sv2 Firmware Wac6103d-i Wac6103d-i Firmware Wac6303d-s Wac6303d-s Firmware Wac6502d-e Wac6502d-e Firmware Wac6502d-s Wac6502d-s Firmware Wac6503d-s Wac6503d-s Firmware Wac6552d-s Wac6552d-s Firmware Wac6553d-s Wac6553d-s Firmware Wax510d Wax510d Firmware Wax610d Wax610d Firmware Wax630s Wax630s Firmware Wax650s Wax650s Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-03T05:03:32.963Z

Reserved: 2022-03-07T00:00:00.000Z

Link: CVE-2022-26532

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-24T06:15:09.390

Modified: 2024-11-21T06:54:07.663

Link: CVE-2022-26532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses