boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-33009

Zyxel Multiple Firewalls
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .2814   98.1   YES
AFFECTED
  Product                     Versions                     Fixed
  ATP series firmware         4.60 through 5.36 Patch 1 –  —
  USG FLEX series firmware    4.60 through 5.36 Patch 1 –  —
  USG FLEX 50(W) firmware     4.60 through 5.36 Patch 1 –  —
  USG20(W)-VPN firmware       4.60 through 5.36 Patch 1 –  —
  VPN series firmware         4.60 through 5.36 Patch 1 –  —
  ZyWALL/USG series firmware  4.60 through 4.73 Patch 1 –  —
TIMELINE
  May 17  Reserved by Zyxel
  May 24  Published (CNA: Zyxel)
  Jun 5   Added to CISA KEV, remediation due 2023-06-26
CWE-120 · CNA: Zyxel · CVSS v3.1 · 2 references · KEV due June 26, 2023

Description

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 17, 2023ReservedReserved by Zyxel
May 24, 2023PublishedPublished (CNA: Zyxel)
June 5, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-06-26

Affected

Affected products and packages — 6 rows
VendorProduct / PackageEcosystemVersion introducedFixed
ZyxelATP series firmware—4.60 through 5.36 Patch 1—
ZyxelUSG FLEX series firmware—4.60 through 5.36 Patch 1—
ZyxelUSG FLEX 50(W) firmware—4.60 through 5.36 Patch 1—
ZyxelUSG20(W)-VPN firmware—4.60 through 5.36 Patch 1—
ZyxelVPN series firmware—4.60 through 5.36 Patch 1—
ZyxelZyWALL/USG series firmware—4.60 through 4.73 Patch 1—

Weaknesses

CWE-120

References (2)

Related

Authoritative record: CVE-2023-33009 at cve.org

Vendors: zyxel

Weaknesses: CWE-120

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-33009 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.