← Vulnerability feed

Vulnerability record · CVE-2023-34140 · published 17 July 2023

CVE-2023-34140: Zyxel usg 20w-vpn firmware classic buffer overflow vulnerability

Zyxel · Usg 20w Vpn Firmware

A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware versions 4.30 through 5.36 Patch 2, NXC2500 firmware versions 6.10(AAIG.0) through 6.10(AAIG.3), and NXC5500 firmware versions 6.10(AAOS.0) through 6.10(AAOS.4), could allow an unauthenticated, LAN-based attacker to cause denial of service (DoS) conditions by sending a crafted request to the CAPWAP daemon.

6.5 CVSS 3.1 Medium EPSS 0.30% · top 79.2% CWE-120 · Classic buffer overflow
6.5CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
24Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware versions 4.30 through 5.36 Patch 2, NXC2500 firmware versions 6.10(AAIG.0) through 6.10(AAIG.3), and NXC5500 firmware versions 6.10(AAOS.0) through 6.10(AAOS.4), could allow an unauthenticated, LAN-based attacker to cause denial of service (DoS) conditions by sending a crafted request to the CAPWAP daemon.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

24 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34140 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-33010Zyxel firewall ID processing buffer overflow allows unauthenticated RCEA classic buffer overflow (CWE-120) exists in the ID processing function of multiple Zyxel firewall firmware lines, including ATP, USG FLEX, USG20(W)…KEVEPSS 29%analysed9.8CVE-2023-33009Zyxel firewall notification function buffer overflowA buffer overflow in the notification function of multiple Zyxel firewall and VPN firmware lines (ATP, USG FLEX, USG20(W)-VPN, VPN, ZyWALL/USG) allow…KEVEPSS 28%analysed9.8CVE-2023-28771Zyxel firewall firmware OS command injection via crafted packetsZyxel ZyWALL/USG, VPN, USG FLEX and ATP series firmware mishandle error messages, allowing OS command injection. An unauthenticated remote attacker c…KEVEPSS 99%analysed9.8CVE-2020-29583Zyxel USG and ATP firmware hard-coded admin credentialZyxel USG and ATP firmware version 4.60 ships an undocumented account (zyfwp) whose password is stored in cleartext in the firmware and cannot be cha…KEVEPSS 90%analysed9.8CVE-2022-0342Zyxel firewall CGI authentication bypass grants admin accessThe CGI program in multiple Zyxel firewall firmware lines (USG/ZyWALL, USG FLEX, ATP, VPN, NSG) fails to properly enforce authentication, allowing a …EPSS 95%analysed9.8CVE-2021-35029Zyxel usg1900 firmware improper authentication vulnerabilityAn authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG …EPSS 2.3%8.8CVE-2023-33011Zyxel usg 2200-vpn firmware vulnerabilityA format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.3…EPSS 0.34%8.8CVE-2023-34139Zyxel usg 2200-vpn firmware os command injection vulnerabilityA command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and …EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2023-34140), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.