CVE-2022-38547: OS Command Injection
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an authenticated attacker with administrator privileges to execute OS commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38547?
CVE-2022-38547 refers to a post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32.
How severe is CVE-2022-38547?
CVE-2022-38547 has a severity rating of 7.2 (high).
Which software versions are affected by CVE-2022-38547?
CVE-2022-38547 affects Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32.
How can I fix CVE-2022-38547?
To fix CVE-2022-38547, it is recommended to update the firmware of Zyxel ZyWALL/USG series to versions 4.73 or higher, VPN series to versions 5.33 or higher, USG FLEX series to versions 5.33 or higher, and ATP series to versions 5.33 or higher.
Where can I find more information about CVE-2022-38547?
You can find more information about CVE-2022-38547 in the Zyxel Security Advisory for Post-Authentication RCE in Firewalls.