Improper access control in ZyXEL Communications Corp. products - CVE-2022-0910
Published: May 24, 2022
Vulnerability identifier: #VU63569
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0910
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the CGI program. A remote attacker can downgrade from two-factor authentication to one-factor authentication via an IPsec VPN client.
Affected software
USG series
USG FLEX series
VPN series
ZyWALL
ATP series
USG FLEX series
VPN series
ZyWALL
ATP series
How to mitigate CVE-2022-0910
Install updates from vendor's website.
USG series - update to 4.72
ZyWALL - update to 4.72
USG FLEX series - update to 5.30
ATP series - update to 5.30
VPN series - update to 5.30
ZyWALL - update to 4.72
USG FLEX series - update to 5.30
ATP series - update to 5.30
VPN series - update to 5.30