Zyxel USG/ZyWALL是中国合勤科技(Zyxel)公司的一款防火墙。 Zyxel USG/ZyWALL 4.20版本至4.70版本、USG FLEX 4.50版本至5.20版本、ATP 4.32版本至5.20版本、VPN 4.30版本至5.20版本、NSG 1.20版本至1.33 Patch 4版本存在安全漏洞,攻击者利用该漏洞绕过Web身份验证并获得设备的管理访问权限。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Zyxel | USG/ZyWALL series firmware | 4.20 through 4.70 | - |
|
| Zyxel | USG FLEX series firmware | 4.50 through 5.20 | - |
|
| Zyxel | ATP series firmware | 4.32 through 5.20 | - |
|
| Zyxel | VPN series firmware | 4.30 through 5.20 | - |
|
| Zyxel | NSG series firmware | 1.20 through 1.33 Patch 4 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0342.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论