A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZyxel Atp100
HWZyxelall versionsZyxel Atp100 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Atp100w
HWZyxelall versionsZyxel Atp100w Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Atp200
HWZyxelall versionsZyxel Atp200 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Atp500
HWZyxelall versionsZyxel Atp500 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Atp700
HWZyxelall versionsZyxel Atp700 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Atp800
HWZyxelall versionsZyxel Atp800 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Usg20 Vpn
HWZyxelall versionsZyxel Usg20 Vpn Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Usg 20w Vpn
HWZyxelall versionsZyxel Usg 20w Vpn Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Usg 40
HWZyxelall versionsZyxel Usg 40 Firmware
OSZyxel4.734.60 – 4.73 (excl.)Zyxel Usg 40w
HWZyxelall versionsZyxel Usg 40w Firmware
OSZyxel4.734.60 – 4.73 (excl.)Zyxel Usg 60
HWZyxelall versionsZyxel Usg 60 Firmware
OSZyxel4.734.60 – 4.73 (excl.)Zyxel Usg 60w
HWZyxelall versionsZyxel Usg 60w Firmware
OSZyxel4.734.60 – 4.73 (excl.)Zyxel Usg Flex 100
HWZyxelall versionsZyxel Usg Flex 100 Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Usg Flex 100w
HWZyxelall versionsZyxel Usg Flex 100w Firmware
OSZyxel5.364.60 – 5.36 (excl.)Zyxel Usg Flex 200
HWZyxelall versionsZyxel Usg Flex 200 Firmware
OSZyxel5.364.60 – 5.36 (excl.)
CISA KEV — detailsi
- Vendori
- Zyxel
- Producti
- Multiple Firewalls
- Added to KEVi
- June 5, 2023
- Remediation deadline (US Federal)i
- June 26, 2023(overdue)
Apply updates per vendor instructions.
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Related vulnerabilities
Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia (firewalle/VPN)
Zyxel Firewall/VPN — zdalny command injection bez uwierzytelnienia (RCE)
Command injection w firmware Zyxel USG FLEX i VPN — zdalne wykonanie poleceń OS
Zyxel USG – ukryte konto z hasłem jawnym w firmware 4.60
Pre-auth command injection w urządzeniach Zyxel NAS — RCE z uprawnieniami root