A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions…
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | ATP series firmware | 4.60 through 5.36 Patch 1 |
| Zyxel | USG FLEX series firmware | 4.60 through 5.36 Patch 1 |
| Zyxel | USG FLEX 50(W) firmware | 4.60 through 5.36 Patch 1 |
| Zyxel | USG20(W) | VPN firmware — 4.60 through 5.36 Patch 1 |
| Zyxel | VPN series firmware | 4.60 through 5.36 Patch 1 |
| Zyxel | ZyWALL/USG series firmware | 4.60 through 4.73 Patch 1 |
Yes — actively exploited. Added to the CISA KEV catalog on 2023-06-05. Ransomware use: Unknown.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.