EXPOSURES › CVE-2022-30525
CVE-2022-30525
HIGH ⌖ ON CISA KEV · EXPLOITEDZyxel firewalls suffered a command injection flaw allowing attackers to execute arbitrary OS commands and modify files.
An OS command injection vulnerability in Zyxel firewall CGI programs let attackers execute arbitrary commands and alter files on vulnerable devices. This is a critical failure for DIB organizations because it directly enables remote code execution, violates CMMC/NIST 800-171 controls around system integrity and access control, and exposes networks to ransomware or data exfiltration. Organizations must verify patch levels on all Zyxel hardware and consider replacing it if patches are unavailable or untrusted.
Shame score — A command injection flaw in a widely deployed firewall product that allows arbitrary OS command execution represents a severe, avoidable security failure with high reputational and compliance impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.