First published: Mon Apr 24 2023(Updated: )
A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote unauthenticated attacker to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel USG Flex 100 firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 100 | ||
Zyxel USG FLEX 100w firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 200 | >=4.50<=5.35 | |
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50(W) series firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 50 | ||
Zyxel USG FLEX 50w | >=4.30<=5.35 | |
Zyxel USG FLEX 50(W) series firmware | ||
Zyxel USG FLEX 500 | >=4.50<=5.35 | |
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX firmware | >=4.50<=5.35 | |
Zyxel USG FLEX 700 firmware | ||
Zyxel VPN100 | >=4.50<=5.35 | |
Zyxel VPN100 Firmware | ||
Zyxel VPN1000 Firmware | >=4.50<=5.35 | |
Zyxel VPN1000 Firmware | ||
Zyxel Zywall VPN 300 Firmware | >=4.50<=5.35 | |
Zyxel Zywall VPN300 | ||
Zyxel Zywall VPN 50 Firmware | >=4.50<=5.35 | |
Zyxel VPN50 Firmware | ||
Zyxel USG 20w-VPN Firmware | >=4.30<=5.35 | |
Zyxel USG20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Zyxel USG FLEX series firmware vulnerability is CVE-2023-22915.
CVE-2023-22915 has a severity rating of 7.5 (High).
CVE-2023-22915 affects Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35.
To fix CVE-2023-22915, it is recommended to update to the latest firmware version provided by Zyxel.
You can find more information about CVE-2023-22915 on Zyxel's official website: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps