CVE-2023-27991: Zyxel ATP100 Firmware

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.

Affected products

  • Zyxel ATP100 Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel ATP100W Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel ATP200 Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel ATP500 Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel ATP700 Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel ATP800 Firmware: from 4.32, before 5.36 (fixed in 5.36)
  • Zyxel USG20-VPN Firmware: from 4.30, before 5.36 (fixed in 5.36)
  • Zyxel Usg 20w-VPN Firmware: from 4.16, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 100 Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 100w Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 200 Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 500 Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 50 Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 50w Firmware: from 4.16, before 5.36 (fixed in 5.36)
  • Zyxel Usg Flex 700 Firmware: from 4.50, before 5.36 (fixed in 5.36)
  • Zyxel VPN1000 Firmware: from 4.30, before 5.36 (fixed in 5.36)
  • Zyxel VPN100 Firmware: from 4.30, before 5.36 (fixed in 5.36)
  • Zyxel VPN300 Firmware: from 4.30, before 5.36 (fixed in 5.36)
  • Zyxel VPN50 Firmware: from 4.30, before 5.36 (fixed in 5.36)

Published 2023-04-24. Last modified 2026-06-17.