Executive brief
A buffer overflow vulnerability exists in the ID processing function of multiple Zyxel firewall series. An unauthenticated remote attacker can exploit this to cause a denial-of-service (DoS) condition or achieve remote code execution.
Affected products
- Zyxel ATP series firmware 4.32 through 5.36 Patch 1
- Zyxel USG FLEX series firmware 4.50 through 5.36 Patch 1
- Zyxel USG FLEX 50(W) firmware 4.25 through 5.36 Patch 1
- Zyxel USG20(W)-VPN firmware 4.25 through 5.36 Patch 1
- Zyxel VPN series firmware 4.30 through 5.36 Patch 1
- Zyxel ZyWALL/USG series firmware 4.25 through 4.73 Patch 1
Timeline
- 2023-06-05: disclosed: Vulnerability published and added to CISA KEV catalog
- 2023-06-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-06: other: Initial NIST analysis completed