LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 5, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 26, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-33010 to its Known Exploited Vulnerabilities catalog on Jun 5, 2023, with a federal patch deadline of Jun 26, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to…

CVE-2023-33010 is a buffer overflow vulnerability affecting multiple Zyxel firewall models, including ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG series. It resides in the ID processing function and can be triggered by an unauthenticated attacker, potentially leading to denial-of-service conditions or remote code execution on the device. Because these appliances often sit at network edges and enforce security policy, compromise can undermine perimeter defenses, disrupt connectivity, or give an attacker a foothold for further movement. Specifics such as exact firmware versions must be confirmed against the vendor advisory.

How it works

The weakness is classified as CWE-120, a classic buffer overflow. In this class of flaw, input is copied into a fixed-size memory buffer without adequate bounds checking. When the supplied data exceeds the allocated space, adjacent memory can be overwritten. On network devices such as firewalls, the ID processing function that handles certain protocol or management identifiers is the reported location of the overflow. An unauthenticated remote attacker can send specially crafted traffic that reaches this function, causing the process to crash (DoS) or, under favorable conditions, to execute attacker-controlled code with the privileges of the affected service. Exact packet formats or trigger conditions are not detailed in the public summary and should not be assumed; defenders must rely on the vendor’s technical description.

Am I affected? How to find it in your systems

These Zyxel firewalls are commonly deployed as perimeter gateways, VPN concentrators, or branch-office security appliances. Inventory every device that matches the listed product families (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, ZyWALL/USG). Check the management interface, CLI, or inventory tooling for the exact model and firmware revision; compare those values against the versions listed in the vendor advisory for CVE-2023-33010. Because the vulnerability is reachable without authentication, any device that exposes the relevant ID-processing path to untrusted networks is at elevated risk. Review firewall logs and system logs for unexpected restarts, process crashes, or anomalous traffic directed at management or VPN ports. Network telemetry showing repeated connection attempts that coincide with device instability may indicate probing or exploitation attempts, though such signs are not unique to this CVE.

How to remediate

The primary remediation is to apply the updates published by Zyxel according to the vendor instructions referenced by CISA. Obtain the fixed firmware for each affected model, verify its integrity, and install it during a maintenance window that allows for validation of connectivity and policy after reboot. After patching, re-inventory the devices to confirm the new firmware level. As additional hardening for this class of vulnerability, restrict management and VPN access to trusted source addresses, disable unused services that might expose the ID-processing path, and ensure that the devices themselves are not reachable from the public internet unless absolutely required. Maintain current backups of configuration so that a clean restore is possible if a device is later found to have been compromised.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure by placing the firewall behind an additional filtering layer or by tightening access-control lists so that only necessary sources can reach the device. If a web application firewall or IPS is available in front of the appliance, enable signatures or virtual-patching rules that target buffer-overflow patterns or anomalous ID-related traffic; confirm any such rules against the vendor’s guidance. Disable non-essential features that rely on the vulnerable ID-processing function if the product documentation permits it. Increase monitoring of the device’s availability, CPU, and process state, and alert on crashes or unexpected reboots. Segment the firewall’s management plane from general user traffic so that an exploit attempt is less likely to reach the vulnerable code path.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on edge devices can lead to full compromise and subsequent data exposure. Although ransomware use of this specific CVE is not documented, treat any confirmed exploitation as a potential breach. Review logs for signs of post-exploitation activity, rotate credentials that may have been stored on or passed through the device, and examine downstream systems for lateral movement. As a quick check for previously leaked credentials, you can run a free exposure scan of your email addresses against known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · Multiple Firewalls
WeaknessCWE-120
Added to CISA KEVJun 5, 2023
Federal patch deadlineJun 26, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities