Record summary

CVE-2022-0342 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 17, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

6
ProductSourceVersion rangeStatus
CVE List4.32 through 5.20affected
CVE List1.20 through 1.33 Patch 4affected
CVE List4.50 through 5.20affected
CVE List4.20 through 4.70affected
CVE List4.30 through 5.20affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALZyxel - Authentication BypassCVSS 9.8

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Impact

Unauthenticated attackers can bypass web authentication and obtain administrative access to Zyxel devices, potentially gaining complete control over firewalls and network security configurations.

Remediation

Apply security updates provided by Zyxel for affected USG/ZyWALL, USG FLEX, ATP, VPN, and NSG series devices.

WeaknessesCWE-287
AuthorsSleepingBag945, Powerexploit
Template tagscve2022cvezyxelauth-bypassroutervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:zyxel:usg40_firmware:*:*:*:*:*:*:*:*
FOFA: body="/2FA-access.cgi" && body="zyxel zyxel_style1"
FOFA: body="/2fa-access.cgi" && body="zyxel zyxel_style1"

Source: ProjectDiscovery

References

2