Unauthenticated Command Injection Vulnerability in Zyxel ATP Series Firmware
CVE-2023-33012

8.8HIGH

Key Information:

Summary

A command injection vulnerability exists within the configuration parser of the Zyxel ATP series and USG FLEX series firmware. This flaw may enable an unauthenticated attacker on the local network to execute arbitrary operating system commands by delivering a specially crafted Generic Routing Encapsulation (GRE) configuration, particularly when the cloud management mode is active. This vulnerability highlights the importance of proper input sanitization within network device firmware to prevent unauthorized access and potential exploitation.

Affected Version(s)

ATP series firmware 5.10 through 5.36 Patch 2

USG FLEX 50(W) series firmware 5.10 through 5.36 Patch 2

USG FLEX series firmware 5.00 through 5.36 Patch 2

References

EPSS Score

24% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.