CVE-2022-0342 Details
Description
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zyxel usg40 firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel usg40 | All versions |
CPE
Remediation
| |
| zyxel usg40w firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel usg40w | All versions |
CPE
Remediation
| |
| zyxel usg60 firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel usg60 | All versions |
CPE
Remediation
| |
| zyxel usg60w firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel usg60w | All versions |
CPE
Remediation
| |
| zyxel zywall 110 firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel zywall 110 | All versions |
CPE
Remediation
| |
| zyxel zywall 310 firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel zywall 310 | All versions |
CPE
Remediation
| |
| zyxel zywall 1100 firmware | >= 4.20, < 4.71 |
CPE
Remediation
| |
| zyxel zywall 1100 | All versions |
CPE
Remediation
| |
| zyxel usg flex 100 firmware | >= 4.50, <= 5.20 |
CPE
Remediation
| |
| zyxel usg flex 100 | All versions |
CPE
Remediation
| |
| zyxel usg flex 200 firmware | >= 4.50, <= 5.20 |
CPE
Remediation
| |
| zyxel usg flex 200 | All versions |
CPE
Remediation
| |
| zyxel usg flex 500 firmware | >= 4.50, <= 5.20 |
CPE
Remediation
| |
| zyxel usg flex 500 | All versions |
CPE
Remediation
| |
| zyxel usg flex 100w firmware | >= 4.50, <= 5.20 |
CPE
Remediation
| |
| zyxel usg flex 100w | All versions |
CPE
Remediation
| |
| zyxel usg flex 700 firmware | >= 4.50, <= 5.20 |
CPE
Remediation
| |
| zyxel usg flex 700 | All versions |
CPE
Remediation
| |
| zyxel atp100 firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp100 | All versions |
CPE
Remediation
| |
| zyxel atp100w firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp100w | All versions |
CPE
Remediation
| |
| zyxel atp200 firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp200 | All versions |
CPE
Remediation
| |
| zyxel atp500 firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp500 | All versions |
CPE
Remediation
| |
| zyxel atp700 firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp700 | All versions |
CPE
Remediation
| |
| zyxel atp800 firmware | >= 4.32, <= 5.20 |
CPE
Remediation
| |
| zyxel atp800 | All versions |
CPE
Remediation
| |
| zyxel vpn50 firmware | >= 4.30, < 5.21 |
CPE
Remediation
| |
| zyxel vpn50 | All versions |
CPE
Remediation
| |
| zyxel vpn100 firmware | >= 4.30, < 5.21 |
CPE
Remediation
| |
| zyxel vpn100 | All versions |
CPE
Remediation
| |
| zyxel vpn300 firmware | >= 4.30, < 5.21 |
CPE
Remediation
| |
| zyxel vpn300 | All versions |
CPE
Remediation
| |
| zyxel vpn1000 firmware | >= 4.30, < 5.21 |
CPE
Remediation
| |
| zyxel vpn1000 | All versions |
CPE
Remediation
| |
| zyxel nsg300 firmware | >= 1.20, < 1.33 1.33 - 1.33 p4 |
CPE
Remediation
| |
| zyxel nsg300 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 4, 2022 | Initial Analysis | [email protected] |