PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-0342

9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
usg/zywall series firmwareusg flex series firmwareatp series firmwarevpn series firmwarensg series firmware
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE history: usg/zywall series firmware

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →