CVE-2023-5960: Zyxel Zld

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.

Affected products

  • Zyxel Zld: from 4.50, up to and including 5.37; from 4.30, up to and including 5.37

Published 2023-11-28. Last modified 2026-06-17.