Medium severity5.5NVD Advisory· Published Nov 28, 2023· Updated Jun 17, 2026
CVE-2023-35136
CVE-2023-35136
Description
An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local attacker to access configuration files on an affected device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- Range: 4.32 - 5.37
- Range: 4.50 - 5.37
- Range: 4.16 - 5.37
- Range: 4.30 - 5.37
- Range: versions 4.32 through 5.37
versions 4.16 through 5.37+ 1 more
- (no CPE)range: versions 4.16 through 5.37
- (no CPE)range: versions 4.50 through 5.37
- Range: versions 4.16 through 5.37
- Range: versions 4.30 through 5.37
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.