U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-26531

Change History

Initial Analysis by NIST 6/06/2022 2:19:16 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:* versions from (including) 4.32 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nap203_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abfa.7\)
     OR
          cpe:2.3:h:zyxel:nap203:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nap303_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abex.7\)
     OR
          cpe:2.3:h:zyxel:nap303:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nap353_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abey.7\)
     OR
          cpe:2.3:h:zyxel:nap353:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nsg100_firmware:*:*:*:*:*:*:*:* versions from (including) 1.00 up to (excluding) 1.33
          *cpe:2.3:o:zyxel:nsg100_firmware:1.33:-:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg100_firmware:1.33:patch1:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg100_firmware:1.33:patch2:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg100_firmware:1.33:patch3:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg100_firmware:1.33:patch4:*:*:*:*:*:*
     OR
          cpe:2.3:h:zyxel:nsg100:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nsg300_firmware:*:*:*:*:*:*:*:* versions from (including) 1.00 up to (excluding) 1.33
          *cpe:2.3:o:zyxel:nsg300_firmware:1.33:-:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg300_firmware:1.33:patch1:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg300_firmware:1.33:patch2:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg300_firmware:1.33:patch3:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg300_firmware:1.33:patch4:*:*:*:*:*:*
     OR
          cpe:2.3:h:zyxel:nsg300:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nsg50_firmware:*:*:*:*:*:*:*:* versions from (including) 1.00 up to (excluding) 1.33
          *cpe:2.3:o:zyxel:nsg50_firmware:1.33:-:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg50_firmware:1.33:patch1:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg50_firmware:1.33:patch2:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg50_firmware:1.33:patch3:*:*:*:*:*:*
          *cpe:2.3:o:zyxel:nsg50_firmware:1.33:patch4:*:*:*:*:*:*
     OR
          cpe:2.3:h:zyxel:nsg50:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa110ax_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abtg.2\)
     OR
          cpe:2.3:h:zyxel:nwa110ax:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa1123-ac-hd_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abin.6\)
     OR
          cpe:2.3:h:zyxel:nwa1123-ac-hd:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa1123-ac-pro_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abhd.7\)
     OR
          cpe:2.3:h:zyxel:nwa1123-ac-pro:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa1123acv3_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abvt.2\)
     OR
          cpe:2.3:h:zyxel:nwa1123acv3:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa1302-ac_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abku.6\)
     OR
          cpe:2.3:h:zyxel:nwa1302-ac:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa210ax_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abtd.2\)
     OR
          cpe:2.3:h:zyxel:nwa210ax:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa50ax_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abyw.5\)
     OR
          cpe:2.3:h:zyxel:nwa50ax:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa5123-ac-hd_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abim.6\)
     OR
          cpe:2.3:h:zyxel:nwa5123-ac-hd:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa55axe_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abzl.5\)
     OR
          cpe:2.3:h:zyxel:nwa55axe:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nwa90ax_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.27\(accv.2\)
     OR
          cpe:2.3:h:zyxel:nwa90ax:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nxc2500_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.10\(aaig.3\)
     OR
          cpe:2.3:h:zyxel:nxc2500:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:nxc5500_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.10\(aaos.3\)
     OR
          cpe:2.3:h:zyxel:nxc5500:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg200_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg200:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg20_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg20:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg210_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg210:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg2200_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg2200:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg300_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg300:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg310_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg310:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_1100_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_1100:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_110_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_110:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_1900_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_1900:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_20w-vpn_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_20w_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_20w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_2200-vpn_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_2200-vpn:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_310_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_310:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_40_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_40:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_40w_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_40w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_60_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_60:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_60w_firmware:*:*:*:*:*:*:*:* versions from (including) 4.09 up to (including) 4.71
     OR
          cpe:2.3:h:zyxel:usg_60w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:* versions from (including) 4.50 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:* versions from (including) 4.50 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:* versions from (including) 4.50 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:* versions from (including) 4.50 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:* versions from (including) 4.50 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:vpn1000_firmware:*:*:*:*:*:*:*:* versions from (including) 4.30 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:vpn1000:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:vpn100_firmware:*:*:*:*:*:*:*:* versions from (including) 4.30 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:vpn100:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:vpn300_firmware:*:*:*:*:*:*:*:* versions from (including) 4.30 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:vpn300:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:vpn50_firmware:*:*:*:*:*:*:*:* versions from (including) 4.30 up to (including) 5.21
     OR
          cpe:2.3:h:zyxel:vpn50:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac500_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abvs.2\)
     OR
          cpe:2.3:h:zyxel:wac500:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac500h_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abwa.2\)
     OR
          cpe:2.3:h:zyxel:wac500h:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac5302d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.10\(abfh.10\)
     OR
          cpe:2.3:h:zyxel:wac5302d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac5302d-sv2_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abvz.6\)
     OR
          cpe:2.3:h:zyxel:wac5302d-sv2:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6103d-i_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(aaxh.7\)
     OR
          cpe:2.3:h:zyxel:wac6103d-i:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6303d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abgl.6\)
     OR
          cpe:2.3:h:zyxel:wac6303d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6502d-e_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(aasd.7\)
     OR
          cpe:2.3:h:zyxel:wac6502d-e:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6502d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(aase.7\)
     OR
          cpe:2.3:h:zyxel:wac6502d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6503d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(aasf.7\)
     OR
          cpe:2.3:h:zyxel:wac6503d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6552d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(abio.7\)
     OR
          cpe:2.3:h:zyxel:wac6552d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wac6553d-s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.25\(aasg.7\)
     OR
          cpe:2.3:h:zyxel:wac6553d-s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wax510d_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abtf.2\)
     OR
          cpe:2.3:h:zyxel:wax510d:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wax610d_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abte.2\)
     OR
          cpe:2.3:h:zyxel:wax610d:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wax630s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abzd.2\)
     OR
          cpe:2.3:h:zyxel:wax630s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:zyxel:wax650s_firmware:*:*:*:*:*:*:*:* versions up to (including) 6.30\(abrm.2\)
     OR
          cpe:2.3:h:zyxel:wax650s:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:L/AC:L/Au:N/C:P/I:P/A:P)
Added CVSS V3.1

								
							
							
						
NIST AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-20
Changed Reference Type
https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml No Types Assigned
https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml Vendor Advisory