CVE-2022-30525General(zyxel / atp100)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-06. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • atp100
  • atp100_firmware
  • atp100w
  • atp100w_firmware

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
atp100atp100_firmwareatp100watp100w_firmwareatp200atp200_firmwareatp500atp500_firmwareatp700atp700_firmware

1 version affected across 32 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-02: 207-02
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2022-30525 — TechTies Inc. Visit -- https://cti.loginsoft.com/ip/45.156.87.165 #Loginsoft #Cytellite #Cybersecurity #CVE202230525 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/yqykiHf7Cv

    Post summary

    The tweet announces a recent detection involving CVE‑2022‑30525 by Cytellite, but it offers no technical details, exploit references, or patch information.

    0000030
    22 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2022-30525 — TechTies Inc. Visit -- https://cti.loginsoft.com/ip/45.156.87.165 #Loginsoft #Cytellite #Cybersecurity #CVE202230525 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/dNntWGAsM2

    Post summary

    Cytellite reports a detection of CVE‑2022‑30525, but offers no proof‑of‑concept, exploit details, or technical information about the vulnerability.

    0000030
    22 followersView on X
CPE platform detail32 entries

32 of 32 entries

PartVendorProductVersionTarget SWTarget HW
HWzyxelatp100---
OSzyxelatp100_firmware---
HWzyxelatp100w---
OSzyxelatp100w_firmware---
HWzyxelatp200---
OSzyxelatp200_firmware---
HWzyxelatp500---
OSzyxelatp500_firmware---
HWzyxelatp700---
OSzyxelatp700_firmware---
HWzyxelatp800---
OSzyxelatp800_firmware---
HWzyxelusg20w-vpn---
OSzyxelusg20w-vpn_firmware---
HWzyxelusg_flex_100w---
OSzyxelusg_flex_100w_firmware---
HWzyxelusg_flex_200---
OSzyxelusg_flex_200_firmware---
HWzyxelusg_flex_500---
OSzyxelusg_flex_500_firmware---
HWzyxelusg_flex_50w---
OSzyxelusg_flex_50w_firmware---
HWzyxelusg_flex_700---
OSzyxelusg_flex_700_firmware---
HWzyxelvpn100---
HWzyxelvpn1000---
OSzyxelvpn1000_firmware---
OSzyxelvpn100_firmware---
HWzyxelvpn300---
OSzyxelvpn300_firmware---
HWzyxelvpn50---
OSzyxelvpn50_firmware---

Explore more