boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-30525

Zyxel Multiple Firewalls
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9994   100.0   YES
AFFECTED
  Product                   Versions                     Fixed
  USG FLEX 100(W) firmware  5.00 through 5.21 Patch 1 –  —
  USG FLEX 200 firmware     5.00 through 5.21 Patch 1 –  —
  USG FLEX 500 firmware     5.00 through 5.21 Patch 1 –  —
  USG FLEX 700 firmware     5.00 through 5.21 Patch 1 –  —
  ATP series firmware       5.10 through 5.21 Patch 1 –  —
  VPN series firmware       4.60 through 5.21 Patch 1 –  —
  USG FLEX 50(W) firmware   5.10 through 5.21 Patch 1 –  —
  USG 20(W)-VPN firmware    5.10 through 5.21 Patch 1 –  —
TIMELINE
  May 10  Reserved by Zyxel
  May 12  Published (CNA: Zyxel)
  May 16  Added to CISA KEV, remediation due 2022-06-06
CWE-78 · CNA: Zyxel · CVSS v3.1 · 6 references · KEV due June 6, 2022

Description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 10, 2022ReservedReserved by Zyxel
May 12, 2022PublishedPublished (CNA: Zyxel)
May 16, 2022KEV ADDEDAdded to CISA KEV, remediation due 2022-06-06

Affected

Affected products and packages — 8 rows
VendorProduct / PackageEcosystemVersion introducedFixed
ZyxelUSG FLEX 100(W) firmware—5.00 through 5.21 Patch 1—
ZyxelUSG FLEX 200 firmware—5.00 through 5.21 Patch 1—
ZyxelUSG FLEX 500 firmware—5.00 through 5.21 Patch 1—
ZyxelUSG FLEX 700 firmware—5.00 through 5.21 Patch 1—
ZyxelATP series firmware—5.10 through 5.21 Patch 1—
ZyxelVPN series firmware—4.60 through 5.21 Patch 1—
ZyxelUSG FLEX 50(W) firmware—5.10 through 5.21 Patch 1—
ZyxelUSG 20(W)-VPN firmware—5.10 through 5.21 Patch 1—

Weaknesses

CWE-78

References (6)

Related

Authoritative record: CVE-2022-30525 at cve.org

Vendors: zyxel

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-30525 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.