← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-2030

A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions 4.16 through 5.30, USG20(W)-VPN firmware versions 4.16 through 5.30, ATP series firmware versions 4.32 through 5.30, VPN series firmware versions 4.30 through 5.30, USG/ZyWALL series firmware versions 4.11 through 4.72, that could allow an authenticated attacker to access some restricted files on a vulnerable device.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
Exploitability:2.9
Impact Score:3.6
EPSS Probability:0.98%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
Zyxel USG FLEX 100(W) firmware 4.50 through 5.30 (affected)
Zyxel USG FLEX 200 firmware 4.50 through 5.30 (affected)
Zyxel USG FLEX 500 firmware 4.50 through 5.30 (affected)
Zyxel USG FLEX 700 firmware 4.50 through 5.30 (affected)
Zyxel ATP series firmware 4.32 through 5.30 (affected)
Zyxel VPN series firmware 4.30 through 5.30 (affected)
Zyxel USG FLEX 50(W) firmware 4.16 through 5.30 (affected)
Zyxel USG 20(W)-VPN firmware 4.16 through 5.30 (affected)
Zyxel USG/ZyWALL series firmware 4.11 through 4.72 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.983%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityZyxel Corporation · Vendor · Taiwan
Reserved2022-06-08T00:00:00
Published2022-07-19T05:55:11
Last Updated2024-08-03T00:24:44

LINK COPIED TO CLIPBOARD