CVE-2023-27991 Details
Description
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zyxel atp200 firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp200 | All versions |
CPE
Remediation
| |
| zyxel atp100 firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp100 | All versions |
CPE
Remediation
| |
| zyxel atp700 firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp700 | All versions |
CPE
Remediation
| |
| zyxel atp500 firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp500 | All versions |
CPE
Remediation
| |
| zyxel atp100w firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp100w | All versions |
CPE
Remediation
| |
| zyxel atp800 firmware | >= 4.32, < 5.36 |
CPE
Remediation
| |
| zyxel atp800 | All versions |
CPE
Remediation
| |
| zyxel usg flex 100 firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 100 | All versions |
CPE
Remediation
| |
| zyxel usg flex 50 firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 50 | All versions |
CPE
Remediation
| |
| zyxel usg flex 200 firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 200 | All versions |
CPE
Remediation
| |
| zyxel usg flex 500 firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 500 | All versions |
CPE
Remediation
| |
| zyxel usg flex 700 firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 700 | All versions |
CPE
Remediation
| |
| zyxel usg flex 100w firmware | >= 4.50, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 100w | All versions |
CPE
Remediation
| |
| zyxel usg 20w-vpn firmware | >= 4.16, < 5.36 |
CPE
Remediation
| |
| zyxel usg 20w-vpn | All versions |
CPE
Remediation
| |
| zyxel usg flex 50w firmware | >= 4.16, < 5.36 |
CPE
Remediation
| |
| zyxel usg flex 50w | All versions |
CPE
Remediation
| |
| zyxel usg20-vpn firmware | >= 4.30, < 5.36 |
CPE
Remediation
| |
| zyxel usg20-vpn | All versions |
CPE
Remediation
| |
| zyxel vpn100 firmware | >= 4.30, < 5.36 |
CPE
Remediation
| |
| zyxel vpn100 | All versions |
CPE
Remediation
| |
| zyxel vpn1000 firmware | >= 4.30, < 5.36 |
CPE
Remediation
| |
| zyxel vpn1000 | All versions |
CPE
Remediation
| |
| zyxel vpn300 firmware | >= 4.30, < 5.36 |
CPE
Remediation
| |
| zyxel vpn300 | All versions |
CPE
Remediation
| |
| zyxel vpn50 firmware | >= 4.30, < 5.36 |
CPE
Remediation
| |
| zyxel vpn50 | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 13, 2023 | Reanalysis | [email protected] |
| Jun 7, 2023 | CPE Deprecation Remap | [email protected] |
| Jun 7, 2023 | CPE Deprecation Remap | [email protected] |
| May 3, 2023 | Initial Analysis | [email protected] |