← Back to browse · API

CVE-2023-33010

Severity
CRITICAL
CVSS
9.8
EPSS
0.28813
Risk score
74.28
CISA KEV
Yes
PoC
No
Published
2023-06-05
Modified
2023-06-05
First seen
2026-08-07
Aliases
EUVD-2023-37199, GHSA-FQV9-84FH-JJGR
Products
Zyxel:ATP series firmware 4.32 through 5.36 Patch 1, Zyxel:Multiple Firewalls, Zyxel:USG FLEX 50(W) firmware 4.25 through 5.36 Patch 1, Zyxel:USG FLEX series firmware 4.50 through 5.36 Patch 1, Zyxel:USG20(W)-VPN firmware 4.25 through 5.36 Patch 1, Zyxel:VPN series Firmware 4.30 through 5.36 Patch 1, Zyxel:ZyWALL/USG series firmware 4.25 through 4.73 Patch 1
Sources
euvd EUVD-2023-37199
cisa.gov CVE-2023-33010

Description

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.

References