Zyxel USG FLEX是中国合勤科技(Zyxel)公司的一款防火墙。提供灵活的 VPN 选项(IPsec、SSL 或 L2TP),为远程工作和管理提供灵活的安全远程访问。 Zyxel产品存在安全漏洞,该漏洞源于CLI命令中发现一个权限升级漏洞,这可能允许本地攻击者在受攻击设备的某些目录中以root权限执行一些操作系统命令。以下产品及版本受到影响:Zyxel USG FLEX 100(W)固件版本4.50至5.30、USG FLEX 200固件版本4.50至5.30、USG FLEX 500固件版本4
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zyxel | USG FLEX 100(W) firmware | 4.50 through 5.30 | - |
|
| Zyxel | USG FLEX 200 firmware | 4.50 through 5.30 | - |
|
| Zyxel | USG FLEX 500 firmware | 4.50 through 5.30 | - |
|
| Zyxel | USG FLEX 700 firmware | 4.50 through 5.30 | - |
|
| Zyxel | ATP series firmware | 4.32 through 5.30 | - |
|
| Zyxel | VPN series firmware | 4.30 through 5.30 | - |
|
| Zyxel | USG FLEX 50(W) firmware | 4.16 through 5.30 | - |
|
| Zyxel | USG 20(W)-VPN firmware | 4.16 through 5.30 | - |
|
| Zyxel | USG/ZyWALL series firmware | 4.09 through 4.72 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Metasploit exploit for CVE-2022-30526 | https://github.com/greek0x0/CVE-2022-30526 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet