Improper Authentication in ZyXEL Communications Corp. products - CVE-2022-0342
Published: March 30, 2022
Vulnerability identifier: #VU61723
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0342
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication checks in the web interface. A remote attacker can bypass authentication process and obtain administrative access to the device.
Affected software
NSG series
ATP series
USG series
VPN series
USG FLEX series
ZyWALL
ATP series
USG series
VPN series
USG FLEX series
ZyWALL
How to mitigate CVE-2022-0342
Install updates from vendor's website.
NSG series - update to 1.33p4_WK11
USG series - update to 4.71
ZyWALL - update to 4.71
VPN series - update to 5.21
USG FLEX series - update to 5.21 Patch 1
ATP series - update to 5.21 Patch 1
USG series - update to 4.71
ZyWALL - update to 4.71
VPN series - update to 5.21
USG FLEX series - update to 5.21 Patch 1
ATP series - update to 5.21 Patch 1