CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2023-33010

CVSS 9.8v3.1pub. 2023-05-24upd. 2025-10-27

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zyxel Atp100

    HW
    Zyxel
    all versions
  • Zyxel Atp100 Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Atp100w

    HW
    Zyxel
    all versions
  • Zyxel Atp100w Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Atp200

    HW
    Zyxel
    all versions
  • Zyxel Atp200 Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Atp500

    HW
    Zyxel
    all versions
  • Zyxel Atp500 Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Atp700

    HW
    Zyxel
    all versions
  • Zyxel Atp700 Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Atp800

    HW
    Zyxel
    all versions
  • Zyxel Atp800 Firmware

    OS
    Zyxel
    5.364.32 – 5.36 (excl.)
  • Zyxel Usg20 Vpn

    HW
    Zyxel
    all versions
  • Zyxel Usg20 Vpn Firmware

    OS
    Zyxel
    5.364.30 – 5.36 (excl.)
  • Zyxel Usg 20w Vpn

    HW
    Zyxel
    all versions
  • Zyxel Usg 20w Vpn Firmware

    OS
    Zyxel
    5.36
  • Zyxel Usg 40

    HW
    Zyxel
    all versions
  • Zyxel Usg 40 Firmware

    OS
    Zyxel
    4.734.25 – 4.73 (excl.)
  • Zyxel Usg 40w

    HW
    Zyxel
    all versions
  • Zyxel Usg 40w Firmware

    OS
    Zyxel
    4.734.25 – 4.73 (excl.)
  • Zyxel Usg 60

    HW
    Zyxel
    all versions
  • Zyxel Usg 60 Firmware

    OS
    Zyxel
    4.734.25 – 4.73 (excl.)
  • Zyxel Usg 60w

    HW
    Zyxel
    all versions
  • Zyxel Usg 60w Firmware

    OS
    Zyxel
    4.734.25 – 4.73 (excl.)
  • Zyxel Usg Flex 100

    HW
    Zyxel
    all versions
  • Zyxel Usg Flex 100 Firmware

    OS
    Zyxel
    5.364.50 – 5.36 (excl.)
  • Zyxel Usg Flex 100w

    HW
    Zyxel
    all versions
  • Zyxel Usg Flex 100w Firmware

    OS
    Zyxel
    5.36
  • Zyxel Usg Flex 200

    HW
    Zyxel
    all versions
  • Zyxel Usg Flex 200 Firmware

    OS
    Zyxel
    5.364.50 – 5.36 (excl.)

CISA KEV — detailsi

Vendori
Zyxel
Producti
Multiple Firewalls
Added to KEVi
June 5, 2023
Remediation deadline (US Federal)i
June 26, 2023(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 26 czerwca 2023
Tags
RCEAuth BypassMemoryVPN
CWE
References

Related vulnerabilities

CVE-2023-33009CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w firmware Zyxel — RCE bez uwierzytelnienia

CVE-2023-28771CRITICAL9.8⚠ KEVPL ✓same product

Zyxel Firewall/VPN — zdalny command injection bez uwierzytelnienia (RCE)

CVE-2022-30525CRITICAL9.8⚠ KEVPL ✓same product

Command injection w firmware Zyxel USG FLEX i VPN — zdalne wykonanie poleceń OS

CVE-2020-29583CRITICAL9.8⚠ KEVPL ✓same product

Zyxel USG – ukryte konto z hasłem jawnym w firmware 4.60

CVE-2020-9054CRITICAL9.8⚠ KEVPL ✓same product

Pre-auth command injection w urządzeniach Zyxel NAS — RCE z uprawnieniami root