Critical flaw in Zyxel firewalls grants access to corporate networks (CVE-2022-30525)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-30525 | OS Command Injection in Zyxel Firewalls Enables Remote Command Execution CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet. Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes. | 9.8 | 100% | KEV PoC ×3 |
| large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices) |
Full article312 words · extracted from helpnetsecurity.com · click to collapse
A critical vulnerability (CVE-2022-30525) affecting several models of Zyxel firewalls has been publicly revealed, along with a Metasploit module that exploits it.
Discovered by Rapid 7 researcher Jake Baines and disclosed to Zyxel on April 13, it was fixed by the company with patches released on April 28, but not publicly acknowledged by the company via an associated CVE or security advisory until now.
About CVE-2022-30525
CVE-2022-30525 is a vulnerability that may be exploited by unauthenticated, remote attackers to inject commands into the OS via the vulnerable firewalls’ administrative HTTP interface (if exposed on the internet), allowing them to modify specific files and execute OS commands.
As confirmed by Zyxel, it affects the following firewall models and firmware versions:
- USG FLEX 100(W), 200, 500, 700 – Firmware: ZLD V5.00 through ZLD V5.21 Patch 1
- USG FLEX 50(W) / USG20(W)-VPN – Firmware: ZLD V5.10 through ZLD V5.21 Patch 1
- ATP series – Firmware: ZLD V5.10 through ZLD V5.21 Patch 1
- VPN series – Firmware: ZLD V4.60 through ZLD V5.21 Patch 1
Fixes and mitigations
With a patch out there that can be reverse-engineered and a Metasploit module available, the 16,000+ vulnerable devices discoverable via Shodan may be targeted by attackers in the coming days and months, perhaps especially by initial access brokers.
Administrators of affected devices are advised to upgrade the firmware to V5.30 as soon as possible.
“If possible, enable automatic firmware updates. Disable WAN access to the administrative web interface of the system,” Baines also advised.
Baines has lamented that Zyxel has patched this vulnerability silently, because this “tends to only help active attackers, and leaves defenders in the dark about the true risk of newly discovered issues.”
Zyxel, though, says it wasn’t on purpose, but due to “miscommunication during the disclosure coordination process.”
UPDATE (May 16, 2022, 06:05 a.m. ET):
Exploitation attempts for CVE-2022-30525 have been detected.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/05/13/cve-2022-30525/