CVE-2023-22917: Zyxel ATP100 Firmware

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.

Affected products

  • Zyxel ATP100 Firmware: from 5.10, up to and including 5.32
  • Zyxel ATP100W Firmware: from 5.10, up to and including 5.32
  • Zyxel ATP200 Firmware: from 5.10, up to and including 5.32
  • Zyxel ATP500 Firmware: from 5.10, up to and including 5.32
  • Zyxel ATP700 Firmware: from 5.10, up to and including 5.32
  • Zyxel ATP800 Firmware: from 5.10, up to and including 5.32
  • Zyxel Usg 20w-VPN Firmware: from 5.10, up to and including 5.32
  • Zyxel Usg Flex 100 Firmware: from 5.00, up to and including 5.32
  • Zyxel Usg Flex 100w Firmware: from 5.00, up to and including 5.32
  • Zyxel Usg Flex 200 Firmware: from 5.00, up to and including 5.32
  • Zyxel Usg Flex 500 Firmware: from 5.00, up to and including 5.32
  • Zyxel Usg Flex 50 Firmware: from 5.00, up to and including 5.32
  • Zyxel Usg Flex 50w Firmware: from 5.10, up to and including 5.32
  • Zyxel Usg Flex 700 Firmware: from 5.00, up to and including 5.32
  • Zyxel VPN1000 Firmware: from 5.00, up to and including 5.35
  • Zyxel VPN100 Firmware: from 5.00, up to and including 5.35
  • Zyxel VPN300 Firmware: from 5.00, up to and including 5.35
  • Zyxel VPN50 Firmware: from 5.00, up to and including 5.35

Published 2023-04-24. Last modified 2026-06-17.