CVE-2022-26413
HIGHZyxel VMG3312-T20A <5.30(ABFX.5)C0 - Command Injection
Title source: llmDescription
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.zyxel.com/support/OS-command-injection-and-buffer-overflow-vulnerabilities-of-CPE-and-ONTs.shtml
Scores
CVSS v3
8.0
EPSS
0.0063
EPSS Percentile
70.4%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (32)
zyxel/ax7501-b0_firmware
< 5.17\(abpc.1\)c0
zyxel/dx5401-b0_firmware
< 5.17\(abyo.1\)c0
zyxel/emg3525-t50b_firmware
< 5.50\(abpm.6\)c0 (2 CPE variants)
zyxel/emg5523-t50b_firmware
< 5.50\(abpm.6\)c0 (2 CPE variants)
zyxel/emg5723-t50k_firmware
< 5.50\(abom.7\)c0
zyxel/emg6726-b10a_firmware
< 5.13\(abnp.7\)c0
zyxel/ep240p_firmware
< 5.40\(abh.0\)c0
zyxel/ex3510-b0_firmware
< 5.17\(abup.4\)c1
zyxel/ex5401-b0_firmware
< 5.17\(abyo.1\)c0
zyxel/ex5501-b0_firmware
< 5.17\(abry.2\)c0
... and 22 more
Published
Apr 11, 2022
Tracked Since
Feb 18, 2026