CVE-2023-22915: Zyxel Usg 20w-VPN Firmware
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote unauthenticated attacker to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device.
Affected products
- Zyxel Usg 20w-VPN Firmware: from 4.30, up to and including 5.35
- Zyxel Usg Flex 100 Firmware: from 4.50, up to and including 5.35
- Zyxel Usg Flex 100w Firmware: from 4.50, up to and including 5.35
- Zyxel Usg Flex 200 Firmware: from 4.50, up to and including 5.35
- Zyxel Usg Flex 500 Firmware: from 4.50, up to and including 5.35
- Zyxel Usg Flex 50 Firmware: from 4.50, up to and including 5.35
- Zyxel Usg Flex 50w Firmware: from 4.30, up to and including 5.35
- Zyxel Usg Flex 700 Firmware: from 4.50, up to and including 5.35
- Zyxel VPN1000 Firmware: from 4.50, up to and including 5.35
- Zyxel VPN100 Firmware: from 4.50, up to and including 5.35
- Zyxel VPN300 Firmware: from 4.50, up to and including 5.35
- Zyxel VPN50 Firmware: from 4.50, up to and including 5.35
Published 2023-04-24. Last modified 2026-06-17.