Zyxel
Zyxel USG 60 Firmware: vulnerabilities and CVEs
Zyxel USG 60 Firmware has 7 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical2
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33009 | Critical (9.8) | 28% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions… |
| CVE-2023-33010 | Critical (9.8) | 29% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33010 | Critical (9.8) | 29% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware… |
| CVE-2023-33009 | Critical (9.8) | 28% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions… |
| CVE-2022-26532 | High (7.8) | 4.8% | — | May 24, 2022 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32… |
| CVE-2022-26531 | High (7.8) | 6.2% | — | May 24, 2022 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware… |
| CVE-2022-0910 | Medium (6.5) | 0.71% | — | May 24, 2022 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through… |
| CVE-2022-0734 | Medium (6.1) | 9.4% | — | May 24, 2022 | A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions… |
| CVE-2018-9129 | Medium (5.9) | 0.97% | — | Aug 15, 2018 | ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Zyxel
Gs1900-10hp Firmware · 35Cloudcnm Secumanager · 35USG Flex 100w Firmware · 34USG Flex 700 Firmware · 34USG Flex 500 Firmware · 34USG Flex 200 Firmware · 34USG Flex 100 Firmware · 30Emg3525-t50b Firmware · 28Vmg8623-t50b Firmware · 28Emg5523-t50b Firmware · 28USG Flex 50W Firmware · 26Atp500 Firmware · 25