Unauthorized Remote Code Execution Vulnerability in Zyxel ATP Series Firmware
CVE-2023-6764
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 20 February 2024
What is CVE-2023-6764?
A format string vulnerability exists in the IPSec VPN feature of Zyxel's firmware, specifically impacting several models within the ATP and USG FLEX series. This vulnerability may allow an attacker to execute unauthorized remote code by utilizing a sequence of specially crafted payloads that exploit an invalid pointer. Successfully carrying out an attack necessitates a comprehensive understanding of the targeted device's memory layout and configuration, potentially making exploitation challenging.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ATP series firmware version 4.32 through 5.37 Patch 1
USG FLEX 50(W) series firmware version 4.16 through 5.37 Patch 1
USG FLEX series firmware version 4.50 through 5.37 Patch 1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved