Zyxel
Zyxel USG Flex 500 Firmware: vulnerabilities and CVEs
Zyxel USG Flex 500 Firmware has 34 published vulnerabilities, 0 of them in the last 12 months. 7 are rated critical and 5 are listed by CISA as actively exploited.
CVEs34
Last 12 months0
Critical7
Actively exploited5
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-33009 | Critical (9.8) | 28% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions… |
| CVE-2023-33010 | Critical (9.8) | 29% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware… |
| CVE-2023-28771 | Critical (9.8) | 99% | ⚠ Active exploitation | Apr 25, 2023 | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series… |
| CVE-2022-30525 | Critical (9.8) | 100% | ⚠ Active exploitation | May 12, 2022 | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00… |
| CVE-2020-29583 | Critical (9.8) | 90% | ⚠ Active exploitation | Dec 22, 2020 | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6764 | High (8.1) | 0.89% | — | Feb 20, 2024 | A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W)… |
| CVE-2023-6399 | Medium (6.5) | 0.65% | — | Feb 20, 2024 | A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16… |
| CVE-2023-6398 | High (7.2) | 1.3% | — | Feb 20, 2024 | A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG… |
| CVE-2023-6397 | Medium (5.3) | 0.30% | — | Feb 20, 2024 | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to… |
| CVE-2023-34141 | High (8) | 0.68% | — | Jul 17, 2023 | A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX… |
| CVE-2023-34140 | Medium (6.5) | 0.30% | — | Jul 17, 2023 | A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36… |
| CVE-2023-34139 | High (8.8) | 0.76% | — | Jul 17, 2023 | A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an… |
| CVE-2023-34138 | High (8) | 0.68% | — | Jul 17, 2023 | A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series… |
| CVE-2023-33012 | High (8.8) | 9.9% | — | Jul 17, 2023 | A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series… |
| CVE-2023-33011 | High (8.8) | 0.34% | — | Jul 17, 2023 | A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36… |
| CVE-2023-28767 | High (8.8) | 0.40% | — | Jul 17, 2023 | The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36, USG FLEX 50(W) series firmware versions… |
| CVE-2023-33010 | Critical (9.8) | 29% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware… |
| CVE-2023-33009 | Critical (9.8) | 28% | ⚠ Active exploitation | May 24, 2023 | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions… |
| CVE-2023-28771 | Critical (9.8) | 99% | ⚠ Active exploitation | Apr 25, 2023 | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series… |
| CVE-2023-27991 | High (8.8) | 1.5% | — | Apr 24, 2023 | The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions… |
| CVE-2023-27990 | Medium (4.8) | 0.34% | — | Apr 24, 2023 | The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN… |
| CVE-2023-22918 | Medium (6.5) | 0.77% | — | Apr 24, 2023 | A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions… |
| CVE-2023-22917 | High (7.5) | 0.88% | — | Apr 24, 2023 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through… |
| CVE-2023-22916 | High (8.1) | 0.69% | — | Apr 24, 2023 | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions… |
| CVE-2023-22915 | High (7.5) | 1.1% | — | Apr 24, 2023 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions… |
| CVE-2023-22914 | High (7.2) | 1.0% | — | Apr 24, 2023 | A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote… |
| CVE-2023-22913 | High (8.1) | 1.3% | — | Apr 24, 2023 | A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which… |
| CVE-2022-38547 | High (7.2) | 2.8% | — | Feb 7, 2023 | A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions… |
| CVE-2022-40603 | Medium (6.1) | 0.39% | — | Dec 6, 2022 | A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50… |
| CVE-2022-30526 | High (7.8) | 1.1% | — | Jul 19, 2022 | A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50… |
| CVE-2022-2030 | Medium (6.5) | 1.4% | — | Jul 19, 2022 | A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX… |
| CVE-2022-26532 | High (7.8) | 4.8% | — | May 24, 2022 | A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32… |
| CVE-2022-26531 | High (7.8) | 6.2% | — | May 24, 2022 | Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware… |
| CVE-2022-0910 | Medium (6.5) | 0.71% | — | May 24, 2022 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through… |
| CVE-2022-0734 | Medium (6.1) | 9.4% | — | May 24, 2022 | A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.