VYPR
High severity8.8NVD Advisory· Published Jul 17, 2023· Updated Jun 17, 2026

CVE-2023-33011

CVE-2023-33011

Description

A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted PPPoE configuration on an affected device when the cloud management mode is enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

31
  • cpe:2.3:o:zyxel:usg_20w-vpn_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:usg_2200-vpn_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_50_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_50w_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:zywall_vpn100_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zyxel:zywall_vpn100_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
    • cpe:2.3:o:zyxel:zywall_vpn_100_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:zywall_vpn2s_firmware:*:*:*:*:*:*:*:*
    Range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:zywall_vpn300_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zyxel:zywall_vpn300_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
    • cpe:2.3:o:zyxel:zywall_vpn_300_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:zywall_vpn50_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:zyxel:zywall_vpn50_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
    • cpe:2.3:o:zyxel:zywall_vpn_50_firmware:*:*:*:*:*:*:*:*range: >=5.00,<5.37
  • cpe:2.3:o:zyxel:zywall_atp100_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:zywall_atp100w_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:zywall_atp200_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:zywall_atp500_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:zywall_atp700_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • cpe:2.3:o:zyxel:zywall_atp800_firmware:*:*:*:*:*:*:*:*
    Range: >=5.10,<5.37
  • Zyxel/ATP seriesllm-fuzzy2 versions
    5.10 - 5.36 Patch 2+ 1 more
    • (no CPE)range: 5.10 - 5.36 Patch 2
    • (no CPE)range: 5.10 through 5.36 Patch 2
  • Zyxel/VPN seriesllm-fuzzy2 versions
    5.00 - 5.36 Patch 2+ 1 more
    • (no CPE)range: 5.00 - 5.36 Patch 2
    • (no CPE)range: 5.00 through 5.36 Patch 2
  • Zyxel/USG FLEX seriescpe-rescue3 versions
    5.00 through 5.36 Patch 2+ 2 more
    • (no CPE)range: 5.00 through 5.36 Patch 2
    • (no CPE)range: 5.10 through 5.36 Patch 2
    • (no CPE)range: 5.00 - 5.36 Patch 2
  • Zyxel/USG20(W)-VPN seriescpe-rescue2 versions
    5.10 through 5.36 Patch 2+ 1 more
    • (no CPE)range: 5.10 through 5.36 Patch 2
    • (no CPE)range: 5.10 - 5.36 Patch 2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.