cbcvebase.
CVE-2023-33012
published 2023-07-17

CVE-2023-33012: A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware…

PriorityP268high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EXPLOIT
EPSS
9.88%
95.1th percentile
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted GRE configuration when the cloud management mode is enabled.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelatp_series_firmware
zyxelusg20_vpn_series_firmware
zyxelusg_20w-vpn_firmware>= 5.10 < 5.375.37
zyxelusg_2200-vpn_firmware>= 5.00 < 5.375.37
zyxelusg_flex_100_firmware>= 5.00 < 5.375.37
zyxelusg_flex_100w_firmware>= 5.00 < 5.375.37
zyxelusg_flex_200_firmware>= 5.00 < 5.375.37
zyxelusg_flex_500_firmware>= 5.00 < 5.375.37
zyxelusg_flex_50_firmware>= 5.00 < 5.375.37
zyxelusg_flex_50_series_firmware
zyxelusg_flex_50w_firmware>= 5.00 < 5.375.37
zyxelusg_flex_700_firmware>= 5.00 < 5.375.37
zyxelusg_flex_series_firmware
zyxelvpn_series_firmware
zyxelzywall_atp100_firmware>= 5.10 < 5.375.37
zyxelzywall_atp100w_firmware>= 5.10 < 5.375.37
zyxelzywall_atp200_firmware>= 5.10 < 5.375.37
zyxelzywall_atp500_firmware>= 5.10 < 5.375.37
zyxelzywall_atp700_firmware>= 5.10 < 5.375.37
zyxelzywall_atp800_firmware>= 5.10 < 5.375.37
zyxelzywall_vpn100_firmware>= 5.00 < 5.375.37
zyxelzywall_vpn2s_firmware>= 5.00 < 5.375.37
zyxelzywall_vpn300_firmware>= 5.00 < 5.375.37
zyxelzywall_vpn50_firmware>= 5.00 < 5.375.37
zyxelzywall_vpn_100_firmware>= 5.00 < 5.375.37

Detection & IOCsextracted from sources · hover to see the quote

filenameparse_config.py
pathmodules/exploits/linux/http/zyxel_parse_config_rce.rb
  • Monitor for crafted GRE configuration payloads submitted to Zyxel devices operating in cloud management mode, which may contain injected OS commands within the configuration parser.
  • The attack originates from the LAN segment and requires no authentication; alert on unexpected OS command execution spawned from the configuration parser process (parse_config.py) on Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, and VPN series devices.
  • A public Metasploit module exists for this CVE targeting the HTTP service on Linux-based Zyxel devices; monitor for exploitation attempts matching the module path linux/http/zyxel_parse_config_rce.
  • ·Exploitation requires cloud management mode to be enabled on the target device; devices not in cloud management mode are not affected by this attack vector.
  • ·The Metasploit module was not tested against a real Zyxel device; it was validated only against a mock environment, so detection fidelity in production may vary.
  • ·Affected firmware version ranges differ per product line (ATP 5.10–5.36 Patch 2; USG FLEX 5.00–5.36 Patch 2; USG FLEX 50(W) 5.10–5.36 Patch 2; USG20(W)-VPN 5.10–5.36 Patch 2; VPN 5.00–5.36 Patch 2); ensure version scoping is accurate before applying detections.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.