CVE-2023-33010
KEVlargeBuffer Overflow in Zyxel ATP, USG FLEX, VPN and ZyWALL/USG Firewalls Enables RCE
CISA: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
CVE-2023-33010 is a buffer overflow (CWE-120) in the ID processing function of Zyxel's firewall firmware that is triggered when an affected device processes crafted input sent by an unauthenticated attacker. Successful exploitation can cause denial-of-service conditions and, more seriously, allow remote code execution on the firewall itself, giving an attacker a foothold at the network perimeter. The flaw affects multiple Zyxel firewall lines widely used by small and mid-sized organizations, including ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and legacy ZyWALL/USG models. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (added 2023-06-05), indicating it is being exploited in the wild, though no public proof-of-concept is known and ransomware association is unconfirmed. EPSS puts the 30-day exploitation probability at 28.8% (98th percentile), and no CVSS score has been published yet.
What to do: Apply the updated firmware for your specific model per Zyxel's security advisory, since the CISA required action is to patch per vendor instructions. Until patched, restrict or disable WAN-side access to the firewall's management/ID processing interfaces and monitor devices for signs of compromise such as unexpected reboots or crashes. Inventory all ATP, USG FLEX (including 50(W)), USG20(W)-VPN, VPN, and ZyWALL/USG units to confirm none remain unpatched.
| Zyxel ATP series firewalls | — |
| Zyxel USG FLEX firewalls | — |
| Zyxel USG FLEX 50(W) firewalls | — |
| Zyxel USG20(W)-VPN firewalls | — |
| Zyxel VPN firewalls | — |
| Zyxel ZyWALL/USG firewalls | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- Affected
- Zyxel Multiple Firewalls
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zyxel
- Products
- atp100 firmware, atp200 firmware, atp500 firmware, atp100w firmware, atp700 firmware, atp800 firmware, usg flex 100 firmware, usg flex 50 firmware, usg flex 200 firmware, usg flex 500 firmware, usg flex 700 firmware, usg flex 100w firmware
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H