GobyVuls/Zyxel/CVE-2022-30525
2022-05-16 11:36:56 +08:00
..
2022-05-16 11:36:56 +08:00

Zyxel ZTP RCE (CVE-2022-30525)

Several firewalls, such as the Zyxel ATP series, VPN series, and USG FLEX series, have security vulnerabilities. An unauthenticated remote attacker could execute arbitrary code on the affected device as the user nobody, taking control of the server.

FOFA query rule: title="USG FLEX" || title="USG20-VPN" || title="USG20W-VPN" || title="ATP100" || title="ATP200" || title="ATP500" || title="ATP700" || title="ATP800"

Demo

Zyxel_ZTP_RCE_CVE_2022_30525