Executive brief
A buffer overflow vulnerability exists in the notification function of multiple Zyxel firewall series. An unauthenticated remote attacker can exploit this to cause a denial-of-service (DoS) condition or execute arbitrary code on the affected device.
Affected products
- Zyxel ATP series firmware 4.60 through 5.36 Patch 1
- Zyxel USG FLEX series firmware 4.60 through 5.36 Patch 1
- Zyxel USG FLEX 50(W) firmware 4.60 through 5.36 Patch 1
- Zyxel USG20(W)-VPN firmware 4.60 through 5.36 Patch 1
- Zyxel VPN series firmware 4.60 through 5.36 Patch 1
- Zyxel ZyWALL/USG series firmware 4.60 through 4.73 Patch 1
Timeline
- 2023-05-24: disclosed: Date based on CVE ID assignment/early reporting context
- 2023-06-05: advisory
- 2023-06-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-05: exploited: Confirmed as exploited in the wild per CISA KEV catalog and advisory.