CVE-2022-26531

Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
ZyxelCNA
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
zyxelvpn100_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn1000_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn300_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn50_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelatp100_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp100w_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp200_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp500_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp700_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp800_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelusg_110_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_1100_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_1900_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_20w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_20w-vpn_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_2200-vpn_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_310_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_40_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_40w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_60_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_60w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_flex_100_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_100w_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_200_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_500_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_700_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg200_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg20_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg210_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg2200_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg300_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg310_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelnsg300_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg300_firmware
1.33
zyxelnsg300_firmware
1.33:patch1
zyxelnsg300_firmware
1.33:patch2
zyxelnsg300_firmware
1.33:patch3
zyxelnsg300_firmware
1.33:patch4
zyxelnsg100_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg100_firmware
1.33
zyxelnsg100_firmware
1.33:patch1
zyxelnsg100_firmware
1.33:patch2
zyxelnsg100_firmware
1.33:patch3
zyxelnsg100_firmware
1.33:patch4
zyxelnsg50_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg50_firmware
1.33
zyxelnsg50_firmware
1.33:patch1
zyxelnsg50_firmware
1.33:patch2
zyxelnsg50_firmware
1.33:patch3
zyxelnsg50_firmware
1.33:patch4
zyxelnxc2500_firmware
𝑥
≤ 6.10\(aaig.3\)
zyxelnxc5500_firmware
𝑥
≤ 6.10\(aaos.3\)
zyxelnap203_firmware
𝑥
≤ 6.25\(abfa.7\)
zyxelnap303_firmware
𝑥
≤ 6.25\(abex.7\)
zyxelnap353_firmware
𝑥
≤ 6.25\(abey.7\)
zyxelnwa50ax_firmware
𝑥
≤ 6.25\(abyw.5\)
zyxelnwa55axe_firmware
𝑥
≤ 6.25\(abzl.5\)
zyxelnwa90ax_firmware
𝑥
≤ 6.27\(accv.2\)
zyxelnwa110ax_firmware
𝑥
≤ 6.30\(abtg.2\)
zyxelnwa210ax_firmware
𝑥
≤ 6.30\(abtd.2\)
zyxelnwa1123-ac-hd_firmware
𝑥
≤ 6.25\(abin.6\)
zyxelnwa1123-ac-pro_firmware
𝑥
≤ 6.25\(abhd.7\)
zyxelnwa1123acv3_firmware
𝑥
≤ 6.30\(abvt.2\)
zyxelnwa1302-ac_firmware
𝑥
≤ 6.25\(abku.6\)
zyxelnwa5123-ac-hd_firmware
𝑥
≤ 6.25\(abim.6\)
zyxelwac500h_firmware
𝑥
≤ 6.30\(abwa.2\)
zyxelwac500_firmware
𝑥
≤ 6.30\(abvs.2\)
zyxelwac5302d-s_firmware
𝑥
≤ 6.10\(abfh.10\)
zyxelwac5302d-sv2_firmware
𝑥
≤ 6.25\(abvz.6\)
zyxelwac6103d-i_firmware
𝑥
≤ 6.25\(aaxh.7\)
zyxelwac6303d-s_firmware
𝑥
≤ 6.25\(abgl.6\)
zyxelwac6502d-e_firmware
𝑥
≤ 6.25\(aasd.7\)
zyxelwac6502d-s_firmware
𝑥
≤ 6.25\(aase.7\)
zyxelwac6503d-s_firmware
𝑥
≤ 6.25\(aasf.7\)
zyxelwac6553d-s_firmware
𝑥
≤ 6.25\(aasg.7\)
zyxelwac6552d-s_firmware
𝑥
≤ 6.25\(abio.7\)
zyxelwax510d_firmware
𝑥
≤ 6.30\(abtf.2\)
zyxelwax610d_firmware
𝑥
≤ 6.30\(abte.2\)
zyxelwax630s_firmware
𝑥
≤ 6.30\(abzd.2\)
zyxelwax650s_firmware
𝑥
≤ 6.30\(abrm.2\)
𝑥
= Vulnerable software versions