vendor:
Zyxel USG/ZyWALL series, USG FLEX series, ATP series, VPN series, NSG series, NXC2500, NAP203, NWA50AX, WAC500, WAX510D
by:
Marco Ivaldi
6.1
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Zyxel USG/ZyWALL series, USG FLEX series, ATP series, VPN series, NSG series, NXC2500, NAP203, NWA50AX, WAC500, WAX510D
Affected Version From: 4.9.2024
Affected Version To: 6.30(ABTF.2)
Patch Exists: YES
Related CWE: CVE-2022-26531
CPE: o:zyxel:usg_firmware:4.71
Platforms Tested:
2022
Zyxel Firmware Multiple Input Validation Vulnerability
The exploit targets Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, and several other firmware versions. An authenticated attacker could exploit the improper input validation flaws in some CLI commands to cause a buffer overflow or system crash with a crafted payload.
Mitigation:
Apply the latest security patches provided by Zyxel to address the input validation flaws and prevent exploitation of buffer overflows.