CVE-2023-33011
A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted PPPoE configuration on an affected device when the cloud management mode is enabled.
Published:Jul 17, 2023
Last Modified:Nov 21, 2024
EPS:Jul 17, 2023
EPSS Score:0.00116
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Atp100 Firmware
Zyxel
Atp100 Firmware
Vendor
Zyxel
Product
Usg20w-vpn Firmware
Zyxel
Usg20w-vpn Firmware
Vendor
Zyxel
Product
Usg 20w-vpn
Zyxel
Usg 20w-vpn
Vendor
Zyxel
Product
Usg 20w-vpn Firmware
Zyxel
Usg 20w-vpn Firmware
Vendor
Zyxel
Product
Usg 2200-vpn
Zyxel
Usg 2200-vpn
Vendor
Zyxel
Product
Usg 2200-vpn Firmware
Zyxel
Usg 2200-vpn Firmware
Vendor
Zyxel
Product
Usg Flex 100
Zyxel
Usg Flex 100
Vendor
Zyxel
Product
Usg Flex 100 Firmware
Zyxel
Usg Flex 100 Firmware
Vendor
Zyxel
Product
Usg Flex 100w
Zyxel
Usg Flex 100w
Vendor
Zyxel
Product
Usg Flex 100w Firmware
Zyxel
Usg Flex 100w Firmware
Vendor
Zyxel
Product
Usg Flex 200
Zyxel
Usg Flex 200
Vendor
Zyxel
Product
Usg Flex 200 Firmware
Zyxel
Usg Flex 200 Firmware
Vendor
Zyxel
Product
Usg Flex 50
Zyxel
Usg Flex 50
Vendor
Zyxel
Product
Usg Flex 500
Zyxel
Usg Flex 500
Vendor
Zyxel
Product
Usg Flex 500 Firmware
Zyxel
Usg Flex 500 Firmware
Vendor
Zyxel
Product
Usg Flex 50\/w\/ Series Firmware
Zyxel
Usg Flex 50\/w\/ Series Firmware
Vendor
Zyxel
Product
Usg Flex 50 Firmware
Zyxel
Usg Flex 50 Firmware
Vendor
Zyxel
Product
Usg Flex 50w
Zyxel
Usg Flex 50w
Vendor
Zyxel
Product
Usg Flex 50w Firmware
Zyxel
Usg Flex 50w Firmware
Vendor
Zyxel
Product
Usg Flex 700
Zyxel
Usg Flex 700
Vendor
Zyxel
Product
Usg Flex 700 Firmware
Zyxel
Usg Flex 700 Firmware
Vendor
Zyxel
Product
Usg Flex Series Firmware
Zyxel
Usg Flex Series Firmware
Vendor
Zyxel
Product
Vpn Series Firmware
Zyxel
Vpn Series Firmware
Vendor
Zyxel
Product
Zywall Atp100
Zyxel
Zywall Atp100
Vendor
Zyxel
Product
Zywall Atp100 Firmware
Zyxel
Zywall Atp100 Firmware
Vendor
Zyxel
Product
Zywall Atp100w
Zyxel
Zywall Atp100w
Vendor
Zyxel
Product
Zywall Atp100w Firmware
Zyxel
Zywall Atp100w Firmware
Vendor
Zyxel
Product
Zywall Atp200
Zyxel
Zywall Atp200
Vendor
Zyxel
Product
Zywall Atp200 Firmware
Zyxel
Zywall Atp200 Firmware
Vendor
Zyxel
Product
Zywall Atp500
Zyxel
Zywall Atp500
Vendor
Zyxel
Product
Zywall Atp500 Firmware
Zyxel
Zywall Atp500 Firmware
Vendor
Zyxel
Product
Zywall Atp700
Zyxel
Zywall Atp700
Vendor
Zyxel
Product
Zywall Atp700 Firmware
Zyxel
Zywall Atp700 Firmware
Vendor
Zyxel
Product
Zywall Atp800
Zyxel
Zywall Atp800
Vendor
Zyxel
Product
Zywall Atp800 Firmware
Zyxel
Zywall Atp800 Firmware
Vendor
Zyxel
Product
Zywall Vpn100
Zyxel
Zywall Vpn100
Vendor
Zyxel
Product
Zywall Vpn100 Firmware
Zyxel
Zywall Vpn100 Firmware
Vendor
Zyxel
Product
Zywall Vpn2s
Zyxel
Zywall Vpn2s
Vendor
Zyxel
Product
Zywall Vpn2s Firmware
Zyxel
Zywall Vpn2s Firmware
Vendor
Zyxel
Product
Zywall Vpn300
Zyxel
Zywall Vpn300
Vendor
Zyxel
Product
Zywall Vpn300 Firmware
Zyxel
Zywall Vpn300 Firmware
Vendor
Zyxel
Product
Zywall Vpn50
Zyxel
Zywall Vpn50
Vendor
Zyxel
Product
Zywall Vpn50 Firmware
Zyxel
Zywall Vpn50 Firmware
Vendor
Zyxel
Product
Zywall Vpn 100
Zyxel
Zywall Vpn 100
Vendor
Zyxel
Product
Zywall Vpn 100 Firmware
Zyxel
Zywall Vpn 100 Firmware
Vendor
Zyxel
Product
Zywall Vpn 300
Zyxel
Zywall Vpn 300
Vendor
Zyxel
Product
Zywall Vpn 300 Firmware
Zyxel
Zywall Vpn 300 Firmware
Vendor
Zyxel
Product
Zywall Vpn 50
Zyxel
Zywall Vpn 50
Vendor
Zyxel
Product
Zywall Vpn 50 Firmware
Zyxel
Zywall Vpn 50 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
