Zyxel Zywall Usg Series Firmware vulnerabilities
5 known vulnerabilities affecting zyxel/zywall_usg_series_firmware.
Total CVEs
5
CISA KEV
3
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-28771P1CRITICALCVSS 9.8KEVPoCv4.60 through 4.732023-04-25
CVE-2023-28771 [CRITICAL] CWE-78 CVE-2023-28771: Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted
nvd
CVE-2023-33010P1CRITICALCVSS 9.8KEVv4.25 through 4.73 Patch 12023-05-24
CVE-2023-33010 [CRITICAL] CWE-120 CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.
nvd
CVE-2023-33009P1CRITICALCVSS 9.8KEVv4.60 through 4.73 Patch 12023-05-24
CVE-2023-33009 [CRITICAL] CWE-120 CVE-2023-33009: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.
nvd
CVE-2022-38547P3HIGHCVSS 7.2v4.20 through 4.722023-02-07
CVE-2022-38547 [HIGH] CWE-78 CVE-2022-38547: A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an authenticated attacker with administrator pr
nvd
CVE-2022-40603P4MEDIUMCVSS 6.1v4.30 through 4.722022-12-06
CVE-2022-40603 [MEDIUM] CWE-79 CVE-2022-40603: A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware ve
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL
nvd