CVE-2022-26413

high-risk
Published 2022-04-11

A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.

Do I need to act?

-
0.63% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.0/10 High
ADJACENT_NETWORK / LOW complexity

Affected Products (20)

Vmg3312-T20A Firmware
Emg6726-B10A Firmware
Vmg1312-T20B Firmware
Vmg3927-B50A Firmware
Vmg3927-B50B Firmware
Vmg3927-B60A Firmware
Vmg4927-B50A Firmware
Vmg8825-B50A Firmware
Vmg8825-B50B Firmware
Vmg8825-B60A Firmware
Vmg8825-B60B Firmware

Affected Vendors

50
/ 100
high-risk
Severity 25/34 · High
Exploitability 2/34 · Minimal
Exposure 23/34 · High