« Back to list

Zyxel

Zyxel USG 60 Firmware: vulnerabilities and CVEs

Zyxel USG 60 Firmware has 7 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.

CVEs7
Last 12 months0
Critical2
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33009Critical (9.8)28%⚠ Active exploitationMay 24, 2023
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions…
CVE-2023-33010Critical (9.8)29%⚠ Active exploitationMay 24, 2023
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-33010Critical (9.8)29%⚠ Active exploitationMay 24, 2023
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware…
CVE-2023-33009Critical (9.8)28%⚠ Active exploitationMay 24, 2023
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions…
CVE-2022-26532High (7.8)4.8%—May 24, 2022
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32…
CVE-2022-26531High (7.8)6.2%—May 24, 2022
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware…
CVE-2022-0910Medium (6.5)0.71%—May 24, 2022
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through…
CVE-2022-0734Medium (6.1)9.4%—May 24, 2022
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions…
CVE-2018-9129Medium (5.9)0.97%—Aug 15, 2018
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Zyxel