LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2023-33009

CVE-2023-33009

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2023-06-05. Federal remediation due 2023-06-26.
Required action: Apply updates per vendor instructions.

Summary

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Zyxel atp100 firmwareZyxel atp100Zyxel atp200 firmwareZyxel atp200Zyxel atp500 firmwareZyxel atp500Zyxel atp100w firmwareZyxel atp100wZyxel atp700 firmwareZyxel atp700Zyxel atp800 firmwareZyxel atp800Zyxel usg flex 100 firmwareZyxel usg flex 100Zyxel usg flex 50 firmwareZyxel usg flex 50Zyxel usg flex 200 firmwareZyxel usg flex 200Zyxel usg flex 500 firmwareZyxel usg flex 500
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-02-26. Always verify against the vendor advisory before acting.

Scroll to Top