PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-30525 Zyxel CVE debrief

CVE-2022-30525 is a Zyxel multiple-firewalls OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-05-16. Because it is listed in KEV, defenders should treat it as actively exploited and prioritize vendor-recommended updates. The supplied corpus does not include affected model lists, firmware versions, or a CVSS score, so remediation should be driven by the vendor guidance referenced by CISA and the official vulnerability records.

Vendor
Zyxel
Product
Multiple Firewalls
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2022-05-16
Original CVE updated
2022-05-16
Advisory published
2022-05-16
Advisory updated
2022-05-16

Who should care

Organizations that operate Zyxel firewall appliances, especially internet-facing deployments, should prioritize this issue. Security teams responsible for edge network devices, vulnerability management, and emergency patching should also care because CISA has marked it as known exploited.

Technical summary

The available official record identifies the issue as an OS command injection vulnerability affecting Zyxel multiple firewalls. The CISA KEV entry confirms the vulnerability is known exploited and directs defenders to apply updates per vendor instructions. The provided corpus does not expose the underlying attack path, impacted firmware range, or exploitation preconditions, so those details should be verified in the vendor advisory and official vulnerability records before any maintenance window is planned.

Defensive priority

High. KEV inclusion means this vulnerability should be remediated on an expedited timeline, with priority given to exposed or externally reachable firewall instances and any devices that cannot be quickly verified as patched.

Recommended defensive actions

  • Identify all Zyxel firewall assets in the environment, including any Internet-facing appliances.
  • Check the vendor advisory and official product guidance referenced by CISA for the correct fixed firmware or update path.
  • Apply the vendor-recommended update as soon as operationally possible.
  • If immediate patching is delayed, reduce exposure by restricting management access and limiting unnecessary inbound access to the device.
  • Verify remediation by confirming installed firmware or software version after maintenance.
  • Monitor affected devices for anomalous command execution, configuration changes, or unexpected administrative activity.

Evidence notes

Facts in this debrief are limited to the supplied CISA KEV record and the official links provided in the corpus. The corpus confirms: vendor project Zyxel, product Multiple Firewalls, vulnerability name 'Zyxel Multiple Firewalls OS Command Injection Vulnerability,' KEV date added 2022-05-16, due date 2022-06-06, and the required action 'Apply updates per vendor instructions.' No CVSS score, affected version list, or exploitation details beyond the OS command injection classification were supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-30525 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-30525

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-30525 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-30525

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.first.org/epss/

    first_epss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.