CVE-2023-33012: Command Injection
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted GRE configuration when the cloud management mode is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel ATP series firmwareto a version that resolves this vulnerability.Fixed in 5.10 through 5.36 Patch 2 - Upgrade
Upgrade
USG FLEX series firmwareto a version that resolves this vulnerability.Fixed in 5.00 through 5.36 Patch 2 - Upgrade
Upgrade
USG FLEX 50(W) series firmwareto a version that resolves this vulnerability.Fixed in 5.10 through 5.36 Patch 2 - Upgrade
Upgrade
USG20(W)-VPN series firmwareto a version that resolves this vulnerability.Fixed in 5.10 through 5.36 Patch 2 - Upgrade
Upgrade
VPN series firmwareto a version that resolves this vulnerability.Fixed in 5.00 through 5.36 Patch 2 - Compensating control
Ensure cloud management mode is not enabled to prevent a LAN-based unauthenticated attacker from executing OS commands via a crafted GRE configuration (applies to the affected Zyxel firmware versions listed with Patch 2).
Event History
Frequently Asked Questions
What is CVE-2023-33012?
CVE-2023-33012 is a command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2.
Which Zyxel products are affected by CVE-2023-33012?
Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, and USG20(W)-VPN series firmware versions 5.00 through 5.37 are affected by CVE-2023-33012.
What is the severity of CVE-2023-33012?
CVE-2023-33012 has a severity rating of 8.8 (high).
How can I fix CVE-2023-33012?
To fix CVE-2023-33012, update the firmware of affected Zyxel products to versions 5.37 or later.
Where can I find more information about CVE-2023-33012?
You can find more information about CVE-2023-33012 in the Zyxel Security Advisory for Multiple Vulnerabilities in Firewalls and WLAN Controllers.