VYPR
High severity8.8NVD Advisory· Published Jul 17, 2023· Updated Jun 17, 2026

CVE-2023-33012

CVE-2023-33012

Description

A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted GRE configuration when the cloud management mode is enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

31

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.