First published: Wed May 24 2023(Updated: )
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Credit: security@zyxel.com.tw security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Multiple Firewalls | ||
Zyxel ATP100 Firmware | >=4.32<5.36 | |
Zyxel ATP100 Firmware | =5.36 | |
Zyxel ATP100 Firmware | =5.36-patch1 | |
Zyxel ATP100 Firmware | ||
Zyxel ATP200 firmware | >=4.32<5.36 | |
Zyxel ATP200 firmware | =5.36 | |
Zyxel ATP200 firmware | =5.36-patch1 | |
Zyxel ATP200 firmware | ||
Zyxel ATP500 Firmware | >=4.32<5.36 | |
Zyxel ATP500 Firmware | =5.36 | |
Zyxel ATP500 Firmware | =5.36-patch1 | |
Zyxel ATP500 Firmware | ||
Zyxel ATP100W Firmware | >=4.32<5.36 | |
Zyxel ATP100W Firmware | =5.36 | |
Zyxel ATP100W Firmware | =5.36-patch1 | |
Zyxel ATP100W Firmware | ||
Zyxel ATP700 Firmware | >=4.32<5.36 | |
Zyxel ATP700 Firmware | =5.36 | |
Zyxel ATP700 Firmware | =5.36-patch1 | |
Zyxel ATP700 Firmware | ||
Zyxel ATP800 | >=4.32<5.36 | |
Zyxel ATP800 | =5.36 | |
Zyxel ATP800 | =5.36-patch1 | |
Zyxel ATP800 Firmware | ||
Zyxel USG Flex 100 firmware | >=4.50<5.36 | |
Zyxel USG Flex 100 firmware | =5.36 | |
Zyxel USG Flex 100 firmware | =5.36-patch1 | |
Zyxel USG FLEX 100 | ||
Zyxel USG FLEX 50(W) series firmware | =5.36 | |
Zyxel USG FLEX 50(W) series firmware | =5.36-patch1 | |
Zyxel USG FLEX 50 | ||
Zyxel USG FLEX 200 | >=4.50<5.36 | |
Zyxel USG FLEX 200 | =5.36 | |
Zyxel USG FLEX 200 | =5.36-patch1 | |
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 500 | >=4.50<5.36 | |
Zyxel USG FLEX 500 | =5.36 | |
Zyxel USG FLEX 500 | =5.36-patch1 | |
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX 700 firmware | >=4.50<5.36 | |
Zyxel USG FLEX 700 firmware | =5.36 | |
Zyxel USG FLEX 700 firmware | =5.36-patch1 | |
Zyxel USG FLEX 700 firmware | ||
Zyxel USG FLEX 100w firmware | =5.36 | |
Zyxel USG FLEX 100w firmware | =5.36-patch1 | |
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 50w | >=4.25<5.36 | |
Zyxel USG FLEX 50w | =5.36 | |
Zyxel USG FLEX 50w | =5.36-patch1 | |
Zyxel USG FLEX 50(W) series firmware | ||
Zyxel USG 20w-VPN Firmware | =5.36 | |
Zyxel USG 20w-VPN Firmware | =5.36-patch1 | |
Zyxel USG20 | ||
Zyxel VPN100 | >=4.30<5.36 | |
Zyxel VPN100 | =5.36 | |
Zyxel VPN100 | =5.36-patch1 | |
Zyxel VPN100 Firmware | ||
Zyxel Zywall VPN 50 Firmware | >=4.30<5.36 | |
Zyxel Zywall VPN 50 Firmware | =5.36 | |
Zyxel Zywall VPN 50 Firmware | =5.36-patch1 | |
Zyxel VPN50 Firmware | ||
Zyxel Zywall VPN 300 Firmware | >=4.30<5.36 | |
Zyxel Zywall VPN 300 Firmware | =5.36 | |
Zyxel Zywall VPN 300 Firmware | =5.36-patch1 | |
Zyxel VPN300 | ||
Zyxel VPN1000 Firmware | >=4.30<5.36 | |
Zyxel VPN1000 Firmware | =5.36 | |
Zyxel VPN1000 Firmware | =5.36-patch1 | |
Zyxel VPN1000 Firmware | ||
Zyxel USG20-VPN Firmware | >=4.30<5.36 | |
Zyxel USG20-VPN Firmware | =5.36 | |
Zyxel USG20-VPN Firmware | =5.36-patch1 | |
Zyxel USG20 | ||
Zyxel USG 40 firmware | >=4.25<4.73 | |
Zyxel USG 40 firmware | =4.73 | |
Zyxel USG 40 firmware | =4.73-patch1 | |
Zyxel USG40W | ||
Zyxel USG40W Firmware | >=4.25<4.73 | |
Zyxel USG40W Firmware | =4.73 | |
Zyxel USG40W Firmware | =4.73-patch1 | |
Zyxel USG40W | ||
Zyxel USG60W Firmware | >=4.25<4.73 | |
Zyxel USG60W Firmware | =4.73 | |
Zyxel USG60W Firmware | =4.73-patch1 | |
Zyxel USG 60w firmware | ||
Zyxel USG60 Firmware | >=4.25<4.73 | |
Zyxel USG60 Firmware | =4.73 | |
Zyxel USG60 Firmware | =4.73-patch1 | |
Zyxel USG60W | ||
All of | ||
Any of | ||
Zyxel ATP100 Firmware | >=4.60<5.36 | |
Zyxel ATP100 Firmware | =5.36 | |
Zyxel ATP100 Firmware | =5.36-patch1 | |
Zyxel ATP100 Firmware | ||
All of | ||
Any of | ||
Zyxel ATP200 firmware | >=4.60<5.36 | |
Zyxel ATP200 firmware | =5.36 | |
Zyxel ATP200 firmware | =5.36-patch1 | |
Zyxel ATP200 firmware | ||
All of | ||
Any of | ||
Zyxel ATP500 Firmware | >=4.60<5.36 | |
Zyxel ATP500 Firmware | =5.36 | |
Zyxel ATP500 Firmware | =5.36-patch1 | |
Zyxel ATP500 Firmware | ||
All of | ||
Any of | ||
Zyxel ATP100W Firmware | >=4.60<5.36 | |
Zyxel ATP100W Firmware | =5.36 | |
Zyxel ATP100W Firmware | =5.36-patch1 | |
Zyxel ATP100W Firmware | ||
All of | ||
Any of | ||
Zyxel ATP700 Firmware | >=4.60<5.36 | |
Zyxel ATP700 Firmware | =5.36 | |
Zyxel ATP700 Firmware | =5.36-patch1 | |
Zyxel ATP700 Firmware | ||
All of | ||
Any of | ||
Zyxel ATP800 | >=4.60<5.36 | |
Zyxel ATP800 | =5.36 | |
Zyxel ATP800 | =5.36-patch1 | |
Zyxel ATP800 Firmware | ||
All of | ||
Any of | ||
Zyxel USG Flex 100 firmware | >=4.60<5.36 | |
Zyxel USG Flex 100 firmware | =5.36 | |
Zyxel USG Flex 100 firmware | =5.36-patch1 | |
Zyxel USG FLEX 100 | ||
All of | ||
Any of | ||
Zyxel USG FLEX 50(W) series firmware | >=4.60<5.36 | |
Zyxel USG FLEX 50(W) series firmware | =5.36 | |
Zyxel USG FLEX 50(W) series firmware | =5.36-patch1 | |
Zyxel USG FLEX 50 | ||
All of | ||
Any of | ||
Zyxel USG FLEX 200 | >=4.60<5.36 | |
Zyxel USG FLEX 200 | =5.36 | |
Zyxel USG FLEX 200 | =5.36-patch1 | |
Zyxel USG FLEX 200 firmware | ||
All of | ||
Any of | ||
Zyxel USG FLEX 500 | >=4.60<5.36 | |
Zyxel USG FLEX 500 | =5.36 | |
Zyxel USG FLEX 500 | =5.36-patch1 | |
Zyxel USG FLEX 500 firmware | ||
All of | ||
Any of | ||
Zyxel USG FLEX 700 firmware | >=4.60<5.36 | |
Zyxel USG FLEX 700 firmware | =5.36 | |
Zyxel USG FLEX 700 firmware | =5.36-patch1 | |
Zyxel USG FLEX 700 firmware | ||
All of | ||
Any of | ||
Zyxel USG Flex 100 firmware | >=4.60<5.36 | |
Zyxel USG FLEX 100w firmware | =5.36 | |
Zyxel USG FLEX 100w firmware | =5.36-patch1 | |
Zyxel USG FLEX 100w firmware | ||
All of | ||
Any of | ||
Zyxel USG FLEX 50w | >=4.60<5.36 | |
Zyxel USG FLEX 50w | =5.36 | |
Zyxel USG FLEX 50w | =5.36-patch1 | |
Zyxel USG FLEX 50(W) series firmware | ||
All of | ||
Any of | ||
Zyxel USG 20w-VPN Firmware | >=4.60<5.36 | |
Zyxel USG 20w-VPN Firmware | =5.36 | |
Zyxel USG 20w-VPN Firmware | =5.36-patch1 | |
Zyxel USG20 | ||
All of | ||
Any of | ||
Zyxel VPN100 | >=4.60<5.36 | |
Zyxel VPN100 | =5.36 | |
Zyxel VPN100 | =5.36-patch1 | |
Zyxel VPN100 Firmware | ||
All of | ||
Any of | ||
Zyxel Zywall VPN 50 Firmware | >=4.60<5.36 | |
Zyxel Zywall VPN 50 Firmware | =5.36 | |
Zyxel Zywall VPN 50 Firmware | =5.36-patch1 | |
Zyxel VPN50 Firmware | ||
All of | ||
Any of | ||
Zyxel Zywall VPN 300 Firmware | >=4.60<5.36 | |
Zyxel Zywall VPN 300 Firmware | =5.36 | |
Zyxel Zywall VPN 300 Firmware | =5.36-patch1 | |
Zyxel VPN300 | ||
All of | ||
Any of | ||
Zyxel VPN1000 Firmware | >=4.60<5.36 | |
Zyxel VPN1000 Firmware | =5.36 | |
Zyxel VPN1000 Firmware | =5.36-patch1 | |
Zyxel VPN1000 Firmware | ||
All of | ||
Any of | ||
Zyxel USG20-VPN Firmware | >=4.60<5.36 | |
Zyxel USG20-VPN Firmware | =5.36 | |
Zyxel USG20-VPN Firmware | =5.36-patch1 | |
Zyxel USG20 | ||
All of | ||
Any of | ||
Zyxel USG 40 firmware | >=4.60<4.73 | |
Zyxel USG 40 firmware | =4.73 | |
Zyxel USG 40 firmware | =4.73-patch1 | |
Zyxel USG40W | ||
All of | ||
Any of | ||
Zyxel USG40W Firmware | >=4.60<4.73 | |
Zyxel USG40W Firmware | =4.73 | |
Zyxel USG40W Firmware | =4.73-patch1 | |
Zyxel USG40W | ||
All of | ||
Any of | ||
Zyxel USG60W Firmware | >=4.60<4.73 | |
Zyxel USG60W Firmware | =4.73 | |
Zyxel USG60W Firmware | =4.73-patch1 | |
Zyxel USG 60w firmware | ||
All of | ||
Any of | ||
Zyxel USG60 Firmware | >=4.60<4.73 | |
Zyxel USG60 Firmware | =4.73 | |
Zyxel USG60 Firmware | =4.73-patch1 | |
Zyxel USG60W |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33009 is a buffer overflow vulnerability in the notification function in Zyxel ATP series, USG FLEX series, USG FLEX 50(W), and USG20(W)-VPN firmware versions 4.32 through 5.36 Patch 1.
CVE-2023-33009 affects Zyxel ATP series, USG FLEX series, USG FLEX 50(W), and USG20(W)-VPN firmware versions 4.32 through 5.36 Patch 1, leading to a buffer overflow vulnerability in the notification function.
CVE-2023-33009 is a buffer overflow vulnerability with a severity rating of high.
Yes, Zyxel has released firmware versions 5.36 Patch 2 and later to address the CVE-2023-33009 vulnerability.
To fix CVE-2023-33009, update your Zyxel firewall's firmware to version 5.36 Patch 2 or later.