.. / CVE-2022-0342

Exploit for Zyxel - Authentication Bypass (CVE-2022-0342)

Description:

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Nuclei Template

View the template here CVE-2022-0342.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0342.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-0342
https://www.zyxel.com/support/Zyxel-security-advisory-for-authentication-bypass-vulnerability-of-firewalls.shtml
https://github.com/murchie85/twitterCyberMonitor
https://github.com/f1tao/awesome-iot-security-resource
https://github.com/gobysec/GobyVuls/blob/master/CVE-2022-0342.md