Taiwanese networking company Zyxel is once again facing a potential security crisis, as many of the company's firewalls are affected by two serious vulnerabilities. Firmware updates are already available and customers are encouraged to install them as soon as possible.

The latest security advisory issued by Zyxel warns customers of multiple buffer overflow vulnerabilities discovered in several of the company's firewall and VPN devices. The Taiwan-based manufacturer says that these two weaknesses can potentially be abused by attackers to execute malicious code or compromise vulnerable networks.
The first security flaw included in Zyxel's advisory is identified as CVE-2023-33009 and is described as a buffer overflow issue in the notification function of the Zyxel ATP series firmware. This flaw could allow an unauthorized attacker to deliver a DoS threat against vulnerable devices or even remotely execute malicious code on the affected firewall device.
The second flaw is tracked as CVE-2023-33010, which is a buffer overflow vulnerability in the ID processing function in the Zyxel ATP series firmware. The flaw could once again allow an unauthenticated attacker to cause a “ DoS” or execute remote code on an affected device. Both issues are classified as “critical” vulnerabilities, with a severity rating of 9.8.

After “thorough” internal investigation, Zyxel said it had identified the firewall series affected by the aforementioned critical vulnerabilities. The devices that are within the “vulnerability support period,” Zyxel said, included the following series:
- ATP, firmware versions ZLD V4.32 to V5.36 Patch 1
- USG FLEX, firmware versions ZLD V4.50 to V5.36 Patch 1
- USG FLEX50(W) / USG20(W)-VPN, firmware versions ZLD V4.25 to V5.36 Patch 1
- VPN, firmware versions ZLD V4.30 to V5.36 Patch 1
- ZyWALL/USG, firmware versions ZLD V4.25 to V4.73 Patch 1
ZyXEL has already released firmware updates to fix the two critical vulnerabilities, and customers should, of course, install the updates as soon as possible to avoid becoming a target for attackers. Black hat hackers and cybercriminals are always looking for vulnerable devices to compromise networks belonging to private or public organizations, and they are usually quite good at finding them.
Information source: techspot.com
