Sploitus

CVE-2022-26531

7 known exploits for CVE-2022-26531

Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware version 6.30(ABTF.2) and earlier versions, that could allow a local authenticated attacker to cause a buffer overflow or a system crash via a crafted payload.

Zyxel vpn100 Firmware
≤ 5.21
CVSS 3.1
7.8 HIGH
EPSS
5.7% (92th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2022-05-24
CVE-2022-26531 at NVD
Authoritative description, scoring and affected products

7 known exploits for CVE-2022-26531

Proof-of-concept code and exploit modules indexed by Sploitus