Unauthenticated Command Injection Vulnerability in Zyxel ATP Series Firmware
CVE-2023-33012
Key Information:
- Vendor
- Zyxel
- Status
- Vendor
- CVE Published:
- 17 July 2023
Summary
A command injection vulnerability exists within the configuration parser of the Zyxel ATP series and USG FLEX series firmware. This flaw may enable an unauthenticated attacker on the local network to execute arbitrary operating system commands by delivering a specially crafted Generic Routing Encapsulation (GRE) configuration, particularly when the cloud management mode is active. This vulnerability highlights the importance of proper input sanitization within network device firmware to prevent unauthorized access and potential exploitation.
Affected Version(s)
ATP series firmware 5.10 through 5.36 Patch 2
USG FLEX 50(W) series firmware 5.10 through 5.36 Patch 2
USG FLEX series firmware 5.00 through 5.36 Patch 2
References
EPSS Score
24% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved