CISA KEV · catalog date Jun 5, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-33009
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through…
Exploited in the wild (CISA KEV since Jun 5, 2023). Zyxel reports CVSS 3.1 9.8. EPSS estimates 28.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- State
- PUBLISHED
- Published
- May 24, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAZyxelOriginal evidence ↗
Record text: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Inspect raw assertion
- Field
container- Value
- A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Firewalls Buffer Overflow Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 28.14% probability · 97.96th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.281440000000; percentile 0.979630000000
FIRST EPSS · score date Aug 27, 2026 · 98th percentile · first observed Aug 27, 2026
Zyxel · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Inspect raw assertion
- Field
container- Value
- A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Firewalls Buffer Overflow Vulnerability
28.14% probability · 97.96th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.281440000000; percentile 0.979630000000
Applicability
Cited product scope
Grouped from 46 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
52 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.60 through 4.73 Patch 1"}]product-1200899350c6986d5c964f597f369618d1abb63616766a4ba3ec511b2ebc27e6Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f7654a1-3806-41c7-82d4-46b0cd7ee53b
product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp100_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c5813b69-c1a3-4695-8b63-17994bba1723
cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
558978ad-8153-4c1f-a6de-ccfbf69f754d
cpe:2.3:o:zyxel:atp100_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b61de8a9-6a73-45ef-8c37-39138f39168a
product-e89e0034d5de943870101b99bf70729bdf104ab7b27b822fa2c5ad4c217de46cLinked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47398fd0-6c5e-4625-9efd-de08c9ab7db2
product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp100w_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3cbaf763-195f-4b36-a450-719931b86650
cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
81cb716a-e996-48a6-8c2d-f4b9398fca77
cpe:2.3:o:zyxel:atp100w_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4cb974ec-859a-4b74-8a60-98a5406e8f43
product-204c039ba605ff99a732d4aeb892002d51199a5a7289e8fc9a6195251cd09d02Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d68a36ff-8caf-401c-9f18-94f3a2405cf4
product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
a32a52f5-5406-4a44-a5c1-42fcdc8c6b22
cpe:2.3:o:zyxel:atp200_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8abed29d-8074-46ab-8a0f-759b0653691b
cpe:2.3:o:zyxel:atp200_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49ff3d01-c9aa-452c-a079-3180dc8db269
product-2aadc23472d0134ca1a46a96d237076a2f79c52ee591e309a631af2c09fe5858Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2818e8ac-ffee-4df9-bf3f-c75166c0e851
product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp500_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9801f3ab-4560-44aa-934f-0a6d31f46195
cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
320fc232-d76c-4d8a-8003-7c9a7a287a4c
cpe:2.3:o:zyxel:atp500_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2a0e5b17-00e0-4cb0-9787-d6a8c8e1e0be
product-cea0f4a3423fb565b7fc5420cfee82db0edf528bf9235d8292671f6e8ae64fe8Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0b41f437-855b-4490-8011-df59887be6d5
product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp700_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cf847a-a858-43a6-b35b-91455682e382
cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
2360f0cc-6958-47b6-87a9-b03d52debaf8
cpe:2.3:o:zyxel:atp700_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9be980d6-9d39-41b9-a35c-1879b72f4146
product-3d53771a3239415f970ae3ae39ad7aea35c319c755ea6e942a0f4add01901eb2Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66b99746-0589-46e6-9cbd-f38619ad97dc
product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp800_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eecc0fb9-ded8-4acf-a627-0537f3ee8c65
cpe:2.3:o:zyxel:atp800_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba1c872c-9192-410d-86f1-55cdf07de77c
cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
6c4ee067-e0f0-49b7-8698-8b1ad8e346f0
product-0bd1e78fe15d29edcff9915f0cb954cead37cc7f3e9a331745ef4c5f1ac121a4Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg20-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7239c54f-ec9e-44b4-ae33-1d36e5448219
product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09eaLinked exactInspect raw assertions
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc69fab1-c862-470a-8cbf-bb8751485611
cpe:2.3:o:zyxel:usg20-vpn_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
e4194305-cca6-4710-94aa-ce0304e1aa44
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8fd54572-2c29-4d2e-b15a-de3a16d8e3ca
product-f9da0300b09cd9131de63e886e3f9279ed620453053ae48caacec872a6bcb053Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6bea412f-3da1-4e91-9c74-0666147dabce
product-41708052d4077bd8f08bf90364c85016ebd5c219f392954a84ed571d11e2981eLinked exactInspect raw assertions
cpe:2.3:o:zyxel:usg_20w-vpn_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 5.36
- Match ID
9c0af7ba-8673-4e69-acec-8c0da8dd417b
cpe:2.3:o:zyxel:usg_20w-vpn_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
107bb5b9-9c04-4c35-88ad-4d59ecd17778
cpe:2.3:o:zyxel:usg_20w-vpn_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5776089e-f9f4-4a0e-a169-fa1fc4dc6329
product-dc2434e70cc224f2b01613a8d8b3e207cd628eccb56370b9f7b02bef542e8e53Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_40:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d84ddb81-de66-4427-8833-633b45a45a14
product-de3d811fd5332d78ee2526236da362690657e554712055ff114d2f22d95fb0b0Linked exactInspect raw assertions
cpe:2.3:o:zyxel:usg_40_firmware:4.73:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa798b77-d4b4-4f21-a543-a6c5aad7878f
cpe:2.3:o:zyxel:usg_40_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.60; through excluding 4.73
- Match ID
aef412be-51e7-4839-b5d3-c4b29dd550ce
cpe:2.3:o:zyxel:usg_40_firmware:4.73:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97239f61-5715-476b-bd20-b40746aafe42
product-cc04a557ace4668ce5eb667c49a464ab6884df0cd1473b9ff517fdf939c0bb19Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_40w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 20 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8f11f36c-60db-4d81-a320-53eee43758c1
Affected-product evidence
Accepted scope and product mapping
23 canonical links · 1 source-reported links
vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0b2bf582a5aa79942527606012ba4ef11a68ad9abca59a4abf071acaeb96106c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
42c316e8-7a5f-422a-a40d-67aa0f2d98c96e952ee3-50dc-4a97-a619-7d1b5c14f8cf918d8ac1-7bdf-4728-a129-d333f5818229vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0c7537a3c4e962c61695d9a69c09c71c4706711aff73126318bc69c88e8d810d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2605494e-8a2c-46b5-942c-afab1f74f7ae2b7d8659-2fde-4084-a900-ee97ba6632e2c140a51d-507a-425b-a408-1f7b82f3c9f0vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-326008e6d320d68bbeba0496f28a5df816c3b4b5fd083259f33968af444d8583
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
112dd004-0f38-487e-939a-5f878f50acba7c926407-9b77-4e47-913c-07d7fcb8c254ded5834d-7b9d-4d72-8e4e-13f768650e16vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-41708052d4077bd8f08bf90364c85016ebd5c219f392954a84ed571d11e2981e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2f647837-fdf4-4173-b194-7837695a2c68bc4cb8f5-6e83-417b-b7cb-fc3c72f2fa32eb8445d8-fe5a-411f-b3a2-109d0798ab7cvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
106c7c2e-dfa2-4524-a4b6-8bbbd96a449941363010-4f8d-4eff-aceb-2f9d0af108637db32257-e164-4c4e-94c3-703cd2310db6vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-5abdfb839c49688aabb3222f4bc5147ec7b4516467e598cdf06c89143c252874
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a084f64b-857d-4307-b741-c0668ac6161ad4a81a5c-13fa-4cce-b33c-019f40dc1f54df103895-9f07-48a4-a23e-748dc4a9988bvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6082442a6083cd87efca032eced3b7c869d191d5abe797ca758b24a14219ab98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c489b77-e01d-46b9-a978-58eafc604ef4d20c77d2-4efd-4452-9149-01bf585402bbe3c817a1-68fe-4e1f-9705-d441d710430cvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7263acb2-01c6-4eac-8967-ff70f4bd88947a093d59-7ebc-46ca-b23a-f7ed155e90d47c2a3c1a-1a8d-4cb6-9c27-48116f1755d5vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-73d8643b6be148d5a452006e63a97198060a54c941b1f1e4638cc41687b261d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
347a0416-dfd7-4c41-9a16-7f7365a2765c384f2492-650c-4469-8016-9900d79d240f65d656f8-a2fa-4d20-838c-3438f4e5275bvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-750c77056e3509254876815ce6785adb86ce7c2ee089bdf23dab5a205a9686fc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
23206548-2457-4dc5-bba8-86beb7b08ab3a9500d02-de74-4e08-a798-cabbfb4d50e5b40067ec-b2c5-4fb5-9068-2ee5aa9b7715vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-86f99bc9ab4d50c9559bddd263642e189da788ee7e254501649990d1e1771b98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
19dcce0f-f8c9-48c5-9002-dff9755448e7a56f841c-10e4-49f5-b0ff-68e6195a38ecb103a83f-db21-4e5a-8327-7ebd25e97131vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-936a8a7c943c7226136a60acef772ee4ce5ac143e5655c668b852f5b8d502342
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c1afd03a-cc2f-4821-baec-d38b8115170cc9fd284b-33e7-45d5-9554-5053b0b1b33fe595b515-4907-4e79-9a78-daec5fe255ddvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
925af85a-f287-4b06-9407-084d95f71b279dc00af8-f13c-41c7-89dd-8ee764794560a3297cef-b2e8-4a36-80bf-8c52f02e296fvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ba391e813d1ca8f48d81faa487ab68073af1b4115a2cc20d0969358c60e0f9ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
948f1281-3ed6-4cbc-ba99-ec4151bfaa11b5fb9e2b-ede5-416a-90ee-88789f74c27bf087e78f-5049-4945-9c1d-0e7317135d00vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a8b9874a-6ab7-4abe-8951-7e3124a015dfbbc78f2f-2fad-41b2-869a-d97b2344315de3d2e4b3-1e5c-4e20-bf0a-e3cc9c129db5vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2cfbdf33-e484-46d0-bca2-814ec9fd959e68d96677-3372-41e4-8051-3f212833d979b3f6f9cc-329f-4b33-bc84-857cb594bfefvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d49cc06bd1694635384653ea5099d635af0950d562113257ca2b986d5033461d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
239cf1b3-700f-4f53-8d1f-dd79cbec558359d9c751-2c59-490e-af55-47e71852fbd5d5753a84-3603-40e7-865b-27e620cb6876vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d781087797ffcbc50b6c52eb91f3e346a66c12189f2fe0f9f13d2c13ec28c3f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8f893bfc-856e-4fd0-b1d2-f09577afe56bcb2f8919-bfa0-4a9b-a3c1-06cb3a603a21dc81ef0f-553c-4e96-ae9e-fd9424a0033dvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-de3d811fd5332d78ee2526236da362690657e554712055ff114d2f22d95fb0b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
685a0c56-b952-4f55-b67f-8e1e63332b82baa4742d-34b2-42d6-8faa-ebde227e4465ff882a85-ade6-4a3d-a73a-50fc2520d99cvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e09b599c8ada399dff2b8ab79fd7bbc40401bd2afbe161b152324fc7a13c2c40
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7ccd3564-c52c-4272-b5d7-d793c659227cca0e9c78-ccd2-4bb5-a134-a2c13402ca49f70d0025-df7d-4931-a8be-4501bf957432vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e4ca10df87762079f9b736c8c1995cdeb765fb4ad23b6ecc52f0bcca7fd863e0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a9a8d3ad-db95-46e4-a40d-3996b51c8522bece45ea-0244-408c-9989-50aabbe73af9f95528a3-55d7-4aea-93f0-c877adc8623fvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09ea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9947accd-e167-4c64-8856-dbc7a6766d3fc155a2ce-46dd-476c-a903-64c5719e9cc8cfcfb3c0-36f3-49c1-a5aa-3e0587267d56vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ee00773-f80b-4c9c-9fc9-5ea2798dc4825e5eeac3-6311-40a2-af54-5b3a7910e63fd53830bc-3cf6-4580-b783-3f058537ca23Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01166061-9858-4bb1-8c84-ef6d1f2ca5434fc5e3b5-f7b6-4736-b3c2-a282134937556e320199-2f63-41b0-b388-4361007e6c6171edffca-ad45-469f-bbe5-0aad935da2a8ad3d9955-163f-4648-aea4-f0dbd9ed791adcd17166-4f9d-4056-846e-437f5671f13fAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
Zyxel
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.