CVE-2022-26532

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to execute arbitrary OS commands by including crafted arguments to the CLI command.
Argument Injection
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ZyxelCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
zyxelvpn100_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn1000_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn300_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelvpn50_firmware
4.30 ≤
𝑥
≤ 5.21
zyxelatp100_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp100w_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp200_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp500_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp700_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelatp800_firmware
4.32 ≤
𝑥
≤ 5.21
zyxelusg_110_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_1100_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_1900_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_20w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_20w-vpn_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_2200-vpn_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_310_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_40_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_40w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_60_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_60w_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg_flex_100_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_100w_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_200_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_500_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg_flex_700_firmware
4.50 ≤
𝑥
≤ 5.21
zyxelusg200_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg20_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg210_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg2200_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg300_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelusg310_firmware
4.09 ≤
𝑥
≤ 4.71
zyxelnsg300_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg300_firmware
1.33
zyxelnsg300_firmware
1.33:patch1
zyxelnsg300_firmware
1.33:patch2
zyxelnsg300_firmware
1.33:patch3
zyxelnsg300_firmware
1.33:patch4
zyxelnsg100_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg100_firmware
1.33
zyxelnsg100_firmware
1.33:patch1
zyxelnsg100_firmware
1.33:patch2
zyxelnsg100_firmware
1.33:patch3
zyxelnsg100_firmware
1.33:patch4
zyxelnsg50_firmware
1.00 ≤
𝑥
< 1.33
zyxelnsg50_firmware
1.33
zyxelnsg50_firmware
1.33:patch1
zyxelnsg50_firmware
1.33:patch2
zyxelnsg50_firmware
1.33:patch3
zyxelnsg50_firmware
1.33:patch4
zyxelnxc2500_firmware
𝑥
≤ 6.10\(aaig.3\)
zyxelnxc5500_firmware
𝑥
≤ 6.10\(aaos.3\)
zyxelnap203_firmware
𝑥
≤ 6.25\(abfa.7\)
zyxelnap303_firmware
𝑥
≤ 6.25\(abex.7\)
zyxelnap353_firmware
𝑥
≤ 6.25\(abey.7\)
zyxelnwa50ax_firmware
𝑥
≤ 6.25\(abyw.5\)
zyxelnwa55axe_firmware
𝑥
≤ 6.25\(abzl.5\)
zyxelnwa90ax_firmware
𝑥
≤ 6.27\(accv.2\)
zyxelnwa110ax_firmware
𝑥
≤ 6.30\(abtg.2\)
zyxelnwa210ax_firmware
𝑥
≤ 6.30\(abtd.2\)
zyxelnwa1123-ac-hd_firmware
𝑥
≤ 6.25\(abin.6\)
zyxelnwa1123-ac-pro_firmware
𝑥
≤ 6.25\(abhd.7\)
zyxelnwa1123acv3_firmware
𝑥
≤ 6.30\(abvt.2\)
zyxelnwa1302-ac_firmware
𝑥
≤ 6.25\(abku.6\)
zyxelnwa5123-ac-hd_firmware
𝑥
≤ 6.25\(abim.6\)
zyxelwac500h_firmware
𝑥
≤ 6.30\(abwa.2\)
zyxelwac500_firmware
𝑥
≤ 6.30\(abvs.2\)
zyxelwac5302d-s_firmware
𝑥
≤ 6.10\(abfh.10\)
zyxelwac5302d-sv2_firmware
𝑥
≤ 6.25\(abvz.6\)
zyxelwac6103d-i_firmware
𝑥
≤ 6.25\(aaxh.7\)
zyxelwac6303d-s_firmware
𝑥
≤ 6.25\(abgl.6\)
zyxelwac6502d-e_firmware
𝑥
≤ 6.25\(aasd.7\)
zyxelwac6502d-s_firmware
𝑥
≤ 6.25\(aase.7\)
zyxelwac6503d-s_firmware
𝑥
≤ 6.25\(aasf.7\)
zyxelwac6553d-s_firmware
𝑥
≤ 6.25\(aasg.7\)
zyxelwac6552d-s_firmware
𝑥
≤ 6.25\(abio.7\)
zyxelwax510d_firmware
𝑥
≤ 6.30\(abtf.2\)
zyxelwax610d_firmware
𝑥
≤ 6.30\(abte.2\)
zyxelwax630s_firmware
𝑥
≤ 6.30\(abzd.2\)
zyxelwax650s_firmware
𝑥
≤ 6.30\(abrm.2\)
𝑥
= Vulnerable software versions