OS Command Injection in ZyXEL Communications Corp. products - CVE-2022-26532
Published: May 24, 2022
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the "packet-trace" CLI command. A local user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
NWA110AX
NWA210AX
NWA1123ACv3
NWA1302-AC
WAC500H
WAC5302D-S
WAC5302D-Sv2
WAC6103D-I
WAC6303D-S
WAC6502D-E
WAC6502D-S
WAC6503D-S
WAC6553D-E
WAC6552D-S
WAX510D
WAX610D
WAX650S
NAP353
NWA50AX
NWA55AXE
NWA90AX
NWA1123-AC-HD
NWA1123-AC-PRO
NWA5123-AC-HD
WAX630S
NAP303
NAP203
NXC5500
NXC2500
USG series
USG FLEX series
VPN series
ATP series
NSG series
ZyWALL
How to mitigate CVE-2022-26532
NAP353 - update to 6.25(ABEY.8)
NWA50AX - update to 6.25(ABYW.8)
NWA55AXE - update to 6.25(ABZL.8)
NWA90AX - update to 6.27(ACCV.3)
NWA110AX - update to 6.30(ABTG.3)
NWA210AX - update to 6.30(ABTD.3)
NWA1123-AC-HD - update to 6.25(ABIN.8)
NWA1123-AC-PRO - update to 6.25(ABHD.8)
NWA1123ACv3 - update to 6.30(ABVT.3)
NWA1302-AC - update to 6.25(ABKU.8)
NWA5123-AC-HD - update to 6.25(ABIM.8)
WAC500H - update to 6.30(ABWA.3)
USG series - update to 4.72
WAC5302D-Sv2 - update to 6.25(ABVZ.8)
WAC6103D-I - update to 6.25(AAXH.8)
WAC6303D-S - update to 6.25(ABGL.8)
WAC6502D-E - update to 6.25(AASD.8)
WAC6502D-S - update to 6.25(AASE.8)
WAC6503D-S - update to 6.25(AASF.8)
WAC6553D-E - update to 6.25(AASG.8)
WAC6552D-S - update to 6.25(ABIO.8)
WAX510D - update to 6.30(ABTF.3)
WAX610D - update to 6.30(ABTE.3)
WAX630S - update to 6.30(ABZD.3)
NAP303 - update to 6.25(ABEX.8)
ATP series - update to 5.30
NSG series - update to 1.33 Patch 5
NAP203 - update to 6.25(ABFA.8)
USG FLEX series - update to 5.30
VPN series - update to 5.30
ZyWALL - update to 4.72
WAX650S - update to 6.30(ABRM.3)