CVE-2022-0342
Zyxel usg40_firmware Improper Authentication
Record summary
CVE-2022-0342 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 17, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
ATP series firmwareBrowse Zyxel / ATP series firmware | CVE List | 4.32 through 5.20 | affected |
NSG series firmwareBrowse Zyxel / NSG series firmware | CVE List | 1.20 through 1.33 Patch 4 | affected |
USG FLEX series firmwareBrowse Zyxel / USG FLEX series firmware | CVE List | 4.50 through 5.20 | affected |
USG/ZyWALL series firmwareBrowse Zyxel / USG/ZyWALL series firmware | CVE List | 4.20 through 4.70 | affected |
VPN series firmwareBrowse Zyxel / VPN series firmware | CVE List | 4.30 through 5.20 | affected |
usg40_firmwareBrowse Zyxel / usg40_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALZyxel - Authentication BypassCVSS 9.8
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Impact
Unauthenticated attackers can bypass web authentication and obtain administrative access to Zyxel devices, potentially gaining complete control over firewalls and network security configurations.
Remediation
Apply security updates provided by Zyxel for affected USG/ZyWALL, USG FLEX, ATP, VPN, and NSG series devices.
Source: ProjectDiscovery