CVE-2023-33009
KEVlargeUnauthenticated Buffer Overflow in Zyxel ATP, USG FLEX and ZyWALL/USG Firewalls
CISA: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
CVE-2023-33009 is an unauthenticated buffer overflow (CWE-120) in the notification function of Zyxel firewall firmware. A remote attacker who can reach the affected device can send crafted input to the notification function without any credentials, overflowing a buffer. Successful exploitation can crash the device (denial of service) and enable remote code execution on the appliance. Affected products are Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG series firewalls, which are commonly deployed as perimeter and VPN gateways in small and mid-size networks. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-06-05, indicating observed exploitation in the wild; no public proof-of-concept is known, and EPSS assigns a 28.1% probability of exploitation within 30 days (98th percentile).
What to do: Apply the fixed firmware for CVE-2023-33009 from Zyxel's security advisory, per the CISA KEV required action (specific fixed versions are not listed in the source data). Until patched, restrict internet exposure of device management, notification, and VPN interfaces and watch for unexpected crashes or reboots on affected ATP, USG FLEX, VPN, or ZyWALL/USG appliances.
| Zyxel ATP series firewalls | — |
| Zyxel USG FLEX series firewalls | — |
| Zyxel USG FLEX 50(W) | — |
| Zyxel USG20(W)-VPN | — |
| Zyxel VPN series firewalls | — |
| Zyxel ZyWALL/USG series firewalls | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- Affected
- Zyxel Multiple Firewalls
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zyxel
- Products
- atp100 firmware, atp200 firmware, atp500 firmware, atp100w firmware, atp700 firmware, atp800 firmware, usg flex 100 firmware, usg flex 50 firmware, usg flex 200 firmware, usg flex 500 firmware, usg flex 700 firmware, usg flex 100w firmware
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H