Executive brief
Improper error message handling in multiple Zyxel firewall series allows an unauthenticated remote attacker to execute OS commands by sending crafted packets to the device. The vulnerability stems from a flaw in the IKE packet decoder.
Affected products
- Zyxel ATP series firmware 4.60 through 5.35
- Zyxel USG FLEX series firmware 4.60 through 5.35
- Zyxel VPN series firmware 4.60 through 5.35
- Zyxel ZyWALL/USG series firmware 4.60 through 4.73
Timeline
- 2023-05-31: disclosed: Vulnerability published and added to CISA KEV catalog
- 2023-05-31: kev added
- 2023-05-31: exploited: Reported as exploited in the wild at time of publication