CVE-2022-26413
high-risk
Published 2022-04-11
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
Do I need to act?
-
0.63% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.0/10
High
ADJACENT_NETWORK
/ LOW complexity
Affected Products (20)
Vmg3312-T20A Firmware
Emg6726-B10A Firmware
Vmg1312-T20B Firmware
Vmg3927-B50A Firmware
Vmg3927-B50B Firmware
Vmg3927-B60A Firmware
Vmg4927-B50A Firmware
Vmg8825-B50A Firmware
Vmg8825-B50B Firmware
Vmg8825-B60A Firmware
Vmg8825-B60B Firmware
Affected Vendors
References (2)
50
/ 100
high-risk
Severity
25/34 · High
Exploitability
2/34 · Minimal
Exposure
23/34 · High