CVE-2022-26413

HIGH

Zyxel VMG3312-T20A <5.30(ABFX.5)C0 - Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.

References (1)

Core 1

Scores

CVSS v3 8.0
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (32)
zyxel/ax7501-b0_firmware < 5.17\(abpc.1\)c0
zyxel/dx5401-b0_firmware < 5.17\(abyo.1\)c0
zyxel/emg3525-t50b_firmware < 5.50\(abpm.6\)c0 (2 CPE variants)
zyxel/emg5523-t50b_firmware < 5.50\(abpm.6\)c0 (2 CPE variants)
zyxel/emg5723-t50k_firmware < 5.50\(abom.7\)c0
zyxel/emg6726-b10a_firmware < 5.13\(abnp.7\)c0
zyxel/ep240p_firmware < 5.40\(abh.0\)c0
zyxel/ex3510-b0_firmware < 5.17\(abup.4\)c1
zyxel/ex5401-b0_firmware < 5.17\(abyo.1\)c0
zyxel/ex5501-b0_firmware < 5.17\(abry.2\)c0
... and 22 more
Published Apr 11, 2022
Tracked Since Feb 18, 2026