References https://nvd.nist.gov/vuln/detail/CVE-2022-26532 https://www.cve.org/CVERecord?id=CVE-2022-26532 https://avd.aliyun.com/detail?id=AVD-2022-26532 https://cve.imfht.com/detail/CVE-2022-26532 https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-ap-controllers-and-aps https://github.com/0xdea/advisories/blob/master/HNS-2022-02-zyxel-zysh.txt https://www.securityweek.com/technical-details-released-recently-patched-zyxel-firewall-vulnerabilities/ https://thehackernews.com/2022/05/zyxel-issues-patches-for-4-new-flaws.html https://cve.imfht.com/detail/CVE-2022-26532?lang=en https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-of-firewalls
Related VulnerabilitiesZyxel Keenetic路由器存在未授权访问漏洞PoCCVE-2018-19326: Zyxel VMG1312-B10D 5.13AAXA.8 - Local File InclusionPoCCVE-2019-12581: Zyxel ZyWal/USG/UAG Devices - Cross-Site ScriptingPoCCVE-2019-12583: Zyxel ZyWall UAG/USG - Account Creation AccessPoCCVE-2019-9955: Zyxel - Cross-Site ScriptingPoCCVE-2020-29583: ZyXel USG - Hardcoded CredentialsPoCCVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code ExecutionPoCCVE-2021-3297: Zyxel NBG2105 V1.00(AAGU.2)C0 - Authentication BypassPoCCVE-2021-46387: Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site ScriptingPoCCVE-2022-0342: Zyxel - Authentication BypassPoCCVE-2022-30525: Zyxel Firewall - OS Command InjectionPoCCVE-2024-29972: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - NsaRescueAngel Backdoor AccountPoCCVE-2024-29973: Zyxel NAS326 Firmware < V5.21(AAZF.17)C0 - Command Injection