Junglewise Threat Intelligence

CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

CVE-2023-33010 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-05

Technologies: Zyxel Multiple Firewalls, Zyxel Firewalls. Vendors: Zyxel.

Executive brief

A buffer overflow vulnerability exists in the ID processing function of multiple Zyxel firewall series. An unauthenticated remote attacker can exploit this to cause a denial-of-service (DoS) condition or achieve remote code execution.

Affected products

  • Zyxel ATP series firmware 4.32 through 5.36 Patch 1
  • Zyxel USG FLEX series firmware 4.50 through 5.36 Patch 1
  • Zyxel USG FLEX 50(W) firmware 4.25 through 5.36 Patch 1
  • Zyxel USG20(W)-VPN firmware 4.25 through 5.36 Patch 1
  • Zyxel VPN series firmware 4.30 through 5.36 Patch 1
  • Zyxel ZyWALL/USG series firmware 4.25 through 4.73 Patch 1

Timeline

  • 2023-06-05: disclosed: Vulnerability published and added to CISA KEV catalog
  • 2023-06-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-06: other: Initial NIST analysis completed

Related threats