PT-2022-17829 · Zyxel · Zyxel Vmg3312-T20A

Published

2022-04-11

·

Updated

2022-04-15

·

CVE-2022-26413

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0
Description A command injection vulnerability in the CGI program could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
Recommendations For Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, consider restricting access to the CGI program until a patch is available. As a temporary workaround, consider disabling the LAN interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26413

Affected Products

Zyxel Vmg3312-T20A