当前位置:网站首页>CVE-2022-30525漏洞复现
CVE-2022-30525漏洞复现
2022-06-09 02:06:00 【初岄】
此文章仅供用于学习研究,严禁用于非法用途,否则后果自负。
CVE-2022-30525
漏洞简介
2022 年 5 月 12 日,Zyxel(合勤)发布安全公告,修复了其防火墙设备中未经身份验证的远程命令注入漏洞(CVE-2022-30525),该漏洞的CVSS评分为9.8。
该漏洞存在于某些Zyxel防火墙版本的 CGI 程序中,允许在未经身份验证的情况下在受影响设备上以nobody用户身份执行任意命令。
目前该漏洞的细节已经公开披露,且相应的Metasploit 模块已经发布,成功利用可以实现文件修改和操作系统命令执行,以获得对网络的初始访问权限并实现横向移动到内部系统。
漏洞影响
| 受影响的型号 | 受影响的固件版本 | 补丁版本 |
|---|---|---|
| USG FLEX 100(W)、200、500、700 | ZLD V5.00 -ZLD V5.21 Patch 1 | ZLD V5.30 |
| USG FLEX 50(W) / USG20(W)-VPN | ZLD V5.10 - ZLD V5.21 Patch 1 | ZLD V5.30 |
| ATP系列 | ZLD V5.10 - ZLD V5.21 Patch 1 | ZLD V5.30 |
| VPN系列 | ZLD V4.60 - ZLD V5.21 Patch 1 | ZLD V5.30 |
漏洞修复
目前Zyxel已经修复了此漏洞ÿ
边栏推荐
- Shell 报告服务器信息
- Create house with UE4 brush BSP
- 不容错过|额度管理与应用-银行信用卡行为评分篇(实操见)
- FRP construction
- 【Unity在Inspector面板修改值时销毁物体或组件】
- [1037. effective boomerang]
- C language vaccine reservation management system
- How to use mongodb database in laravel framework
- Official account mall system makes e-commerce easier!
- Diffusion model has been very popular in the field of image generation recently. How do you think its popularity has begun to surpass Gan?
猜你喜欢

浮點數詳解(一篇徹底學通浮點數)

MySQL starts the binlog log to recover the erroneously deleted tables, data and MySQL database

【Unity在Inspector面板修改值时销毁物体或组件】

jenkins根据凭证ID查看忘记的凭证密码以及重置admin密码的操作方法

Zhihu hot discussion: at the age of 35, do you want to escape Beijing, Shanghai and Guangzhou?

Detailed explanation of floating point numbers (a thorough study of floating point numbers)

Implementation of UESTC daily report based on Selenium
![[MVC idea in unity -- using MVC to make UI logic]](/img/1b/7c07d68bb3491b69eb905f281216d8.png)
[MVC idea in unity -- using MVC to make UI logic]

【刷穿剑指】剑指 Offer II 003. 前 n 个数字二进制中 1 的个数

在苹果和三星都降价超千元后,国产手机坐不住了纷纷降价抛货
随机推荐
Requires SQLite 3.8.3 or higher error in CentOS
Swift GCD DispatchGroup Notify wait DispatchSourceTimer Monitor system file Two apps communicate
shell 获取 IP 位置
win10 重命名用户文件夹
Implementation of UESTC daily report based on Selenium
intel 加速云数智变革
浮点数详解(一篇彻底学通浮点数)
GCD Locks Dead cycle SpinLock synchronized
GDB notes (10) - check for memory leak, heap overflow, stack overflow, global memory overflow, and continue using after release
Phar deserialization learning swpuctf2018 simplephp
Diffusion model最近在圖像生成領域大紅大紫,如何看待它的風頭開始超過GAN?
Jenkins can view the forgotten credential password based on the credential ID and how to reset the admin password
[brush through sword finger] sword finger offer II 003 Number of 1 in the first n digit binary
Thread synchronization, process synchronization, mutex, semaphore, condition variable, etc
How to improve the click through rate of push messages through a/b testing?
Lvs+keepalived high availability
[wustctf 2020] plain
QT epidemic information management system
About database: vba+sql uses select * from a where name1 regexp to 'protect', and the error prompt is "operator missing"
Former Disney executive says Depp will return to pirates of the Caribbean to continue playing Captain