Description
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on the affected device by passing a crafted string as an argument to a CLI command.
Published: 2025-10-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel atp100
Zyxel atp100w
Zyxel atp200
Zyxel atp500
Zyxel atp700
Zyxel atp800
Zyxel usg 20w-vpn
Zyxel usg Flex 100
Zyxel usg Flex 100ax
Zyxel usg Flex 100w
Zyxel usg Flex 200
Zyxel usg Flex 50
Zyxel usg Flex 500
Zyxel usg Flex 50ax
Zyxel usg Flex 50w
Zyxel usg Flex 700
Zyxel zld
CPEs cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_20w-vpn:*:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100ax:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50ax:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
Vendors & Products Zyxel atp100
Zyxel atp100w
Zyxel atp200
Zyxel atp500
Zyxel atp700
Zyxel atp800
Zyxel usg 20w-vpn
Zyxel usg Flex 100
Zyxel usg Flex 100ax
Zyxel usg Flex 100w
Zyxel usg Flex 200
Zyxel usg Flex 50
Zyxel usg Flex 500
Zyxel usg Flex 50ax
Zyxel usg Flex 50w
Zyxel usg Flex 700
Zyxel zld

Tue, 21 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel atp Series Firmware
Zyxel usg20(w)-vpn Series Firmware
Zyxel usg Flex 50(w) Series Firmware
Zyxel usg Flex Series Firmware
Vendors & Products Zyxel
Zyxel atp Series Firmware
Zyxel usg20(w)-vpn Series Firmware
Zyxel usg Flex 50(w) Series Firmware
Zyxel usg Flex Series Firmware

Tue, 21 Oct 2025 02:30:00 +0000

Type Values Removed Values Added
Description A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on the affected device by passing a crafted string as an argument to a CLI command.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zyxel Atp100 Atp100w Atp200 Atp500 Atp700 Atp800 Atp Series Firmware Usg20(w)-vpn Series Firmware Usg 20w-vpn Usg Flex 100 Usg Flex 100ax Usg Flex 100w Usg Flex 200 Usg Flex 50 Usg Flex 50(w) Series Firmware Usg Flex 500 Usg Flex 50ax Usg Flex 50w Usg Flex 700 Usg Flex Series Firmware Zld
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-02-26T16:57:22.696Z

Reserved: 2025-07-23T09:10:08.765Z

Link: CVE-2025-8078

cve-icon Vulnrichment

Updated: 2025-10-21T13:42:53.035Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-21T03:15:35.517

Modified: 2025-10-28T19:36:21.637

Link: CVE-2025-8078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T09:39:28Z

Weaknesses