CVE-2022-26413: OS Command Injection
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26413?
CVE-2022-26413 has a high severity rating due to its potential to allow local authenticated attackers to execute arbitrary OS commands.
How do I fix CVE-2022-26413?
To fix CVE-2022-26413, it is recommended to update the Zyxel VMG3312-T20A firmware to a version that is not vulnerable.
What devices are affected by CVE-2022-26413?
CVE-2022-26413 specifically affects Zyxel VMG3312-T20A devices running firmware version 5.30(ABFX.5)C0.
Can I exploit CVE-2022-26413 remotely?
No, CVE-2022-26413 requires local authenticated access to exploit the vulnerability.
What types of attacks can be performed using CVE-2022-26413?
CVE-2022-26413 allows attackers to execute arbitrary OS commands on the affected device, which could lead to further system compromise.