CVE-2023-33011: High severity Zyxel Usg 2200-vpn Firmware vulnerability
A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted PPPoE configuration on an affected device when the cloud management mode is enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33011?
CVE-2023-33011 is a format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2.
Which Zyxel firmware versions are affected by CVE-2023-33011?
The Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN.
What is the severity of CVE-2023-33011?
CVE-2023-33011 has a severity rating of 8.8 (High).
How can I fix CVE-2023-33011?
To fix CVE-2023-33011, update your Zyxel firmware to version 5.37 or higher.
Where can I find more information about CVE-2023-33011?
More information about CVE-2023-33011 can be found in the Zyxel Security Advisory.