📦 Usg Flex 50 Firmware

by Zyxel

🔍 What is Usg Flex 50 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-33009

CRITICAL CVSS 9.8 May 24, 2023

A buffer overflow vulnerability in Zyxel firewall notification functions allows unauthenticated attackers to cause denial-of-service or execute arbitrary code remotely. This affects multiple Zyxel fir...

CVE-2023-28771

CRITICAL CVSS 9.8 Apr 25, 2023

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected Zyxel firewall devices by sending specially crafted IKE packets. It affects multip...

CVE-2023-6764

HIGH CVSS 8.1 Feb 20, 2024

A format string vulnerability in the IPSec VPN feature of Zyxel firewall and VPN devices allows remote code execution. Attackers could execute arbitrary code on affected devices by sending specially c...

CVE-2023-6398

HIGH CVSS 7.2 Feb 20, 2024

This CVE describes a post-authentication command injection vulnerability in Zyxel firewall and access point firmware. An authenticated attacker with administrator privileges can execute OS commands on...

CVE-2023-33012

HIGH CVSS 8.8 Jul 17, 2023

An unauthenticated LAN-based attacker can execute arbitrary OS commands on affected Zyxel network devices by sending a malicious GRE configuration when cloud management is enabled. This affects multip...

CVE-2023-34139

HIGH CVSS 8.8 Jul 17, 2023

An unauthenticated command injection vulnerability in the Free Time WiFi hotspot feature of Zyxel USG FLEX and VPN series firewalls allows LAN-based attackers to execute arbitrary operating system com...

CVE-2023-34141

HIGH CVSS 8.0 Jul 17, 2023

This CVE describes a command injection vulnerability in Zyxel firewall and WLAN controller products that allows LAN-based attackers to execute arbitrary OS commands. Attackers must first trick an auth...

CVE-2023-28767

HIGH CVSS 8.8 Jul 17, 2023

This vulnerability allows an unauthenticated attacker on the local network to inject OS commands into the configuration data of affected Zyxel devices when cloud management is enabled. It affects mult...

CVE-2023-27991

HIGH CVSS 8.8 Apr 24, 2023

This is a post-authentication command injection vulnerability in Zyxel firewall CLI commands that allows authenticated attackers to execute arbitrary operating system commands remotely. It affects mul...

CVE-2023-22913

HIGH CVSS 8.1 Apr 24, 2023

A post-authentication command injection vulnerability in Zyxel USG FLEX and VPN series firewalls allows authenticated attackers to execute arbitrary commands through the account_operator.cgi program. ...

CVE-2023-22915

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in the fbwifi_forward.cgi CGI program of affected Zyxel devices allows remote unauthenticated attackers to cause denial-of-service conditions by sending crafted HTTP re...

CVE-2023-22917

HIGH CVSS 7.5 Apr 24, 2023

A buffer overflow vulnerability in Zyxel network devices allows remote unauthenticated attackers to cause denial of service by uploading a crafted configuration file. This affects multiple Zyxel firew...

CVE-2022-38547

HIGH CVSS 7.2 Feb 7, 2023

This is a post-authentication command injection vulnerability in Zyxel firewall devices that allows authenticated administrators to execute arbitrary operating system commands. It affects multiple Zyx...