Buffer overflow in ZyXEL Communications Corp. products - CVE-2023-33010
Published: May 25, 2023 / Updated: June 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the ID processing function. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
USG series
VPN series
USG FLEX series
ZyWALL
USG20W-VPN
USG FLEX 50W
How to mitigate CVE-2023-33010
USG series - update to 4.73 Patch 2
ZyWALL - update to 4.73 Patch 2
VPN series - update to 5.36 Patch 2
USG20W-VPN - update to 5.36 Patch 2
USG FLEX 50W - update to 5.36 Patch 2
USG FLEX series - update to 5.36 Patch 2