CVE-2022-30525 is a critical OS command injection vulnerability (CWE-78) affecting multiple Zyxel USG FLEX, ATP, and VPN series firewall firmware versions. This flaw allows an unauthenticated attacker to execute arbitrary OS commands on vulnerable devices by modifying specific files. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating extremely high exploitability, this vulnerability poses a severe risk, enabling full compromise of affected systems. It is actively exploited in the wild, with public exploit code available in Metasploit and Nuclei, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.00, < 5.30CPE matchmatch criteria | cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:* | ||
>= 5.00, < 5.30CPE matchmatch criteria | cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:* | ||
>= 5.00, <= 5.30CPE matchmatch criteria | cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:* | ||
>= 5.00, < 5.30CPE matchmatch criteria | cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:* | ||
>= 4.60, < 5.30CPE matchmatch criteria | cpe:2.3:o:zyxel:vpn100_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.