CVE-2025-8078
7.2Zyxel · ATP, USG FLEX, and USG20-VPN series firewalls
An authenticated command injection vulnerability in Zyxel firewall firmware allows an attacker with administrator privileges to execute OS commands via a crafted CLI command string.
Executive summary
A critical post-authentication command injection vulnerability in multiple Zyxel firewall series allows administrative attackers to achieve full system command execution.
Vulnerability
This vulnerability is a classic OS Command Injection (CWE-78) triggered by passing a malicious string into a CLI command argument. The flaw requires the attacker to possess administrative credentials to the device, at which point they can execute arbitrary OS commands.
Business impact
Successful exploitation of this flaw grants an attacker complete control over the affected firewall, leading to potential data exfiltration, network traffic interception, or the deployment of persistent threats within the perimeter. With a CVSS score of 7.2, this vulnerability represents a significant risk to organizational infrastructure, as it essentially allows an attacker to compromise the security gateway protecting the internal network.
Remediation
Immediate Action: Review the official Zyxel security advisory for available firmware patches and apply them to all affected firewall models immediately.
Proactive Monitoring: Monitor system logs for unusual CLI activity or unexpected configuration changes that may indicate an attempt to inject malicious commands.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and enforce strong multi-factor authentication for all administrative accounts to mitigate the risk of credential compromise.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of network firewalls, organizations must prioritize the identification of affected hardware and the application of vendor-provided updates. Administrators should treat this vulnerability with high urgency, ensuring that management interfaces are secured and that any available patches are deployed during the next maintenance window to prevent potential unauthorized system access.