CISA KEV · catalog date Jun 5, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-33010
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through…
Exploited in the wild (CISA KEV since Jun 5, 2023). NVD reports CVSS 3.1 9.8. EPSS estimates 28.8% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- State
- PUBLISHED
- Published
- May 24, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAZyxelOriginal evidence ↗
Record text: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Inspect raw assertion
- Field
container- Value
- A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Firewalls Buffer Overflow Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 28.81% probability · 98.01th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.288130000000; percentile 0.980050000000
FIRST EPSS · score date Aug 27, 2026 · 98th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Inspect raw assertion
- Field
container- Value
- A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Zyxel Multiple Firewalls Buffer Overflow Vulnerability
28.81% probability · 98.01th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.288130000000; percentile 0.980050000000
Applicability
Cited product scope
Grouped from 46 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
52 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.32 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.25 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.25 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.50 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.30 through 5.36 Patch 1"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.25 through 4.73 Patch 1"}]product-1200899350c6986d5c964f597f369618d1abb63616766a4ba3ec511b2ebc27e6Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f7654a1-3806-41c7-82d4-46b0cd7ee53b
product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp100_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b61de8a9-6a73-45ef-8c37-39138f39168a
cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
73e39b94-291e-4e3a-8a89-b74ff063ba05
cpe:2.3:o:zyxel:atp100_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c5813b69-c1a3-4695-8b63-17994bba1723
product-e89e0034d5de943870101b99bf70729bdf104ab7b27b822fa2c5ad4c217de46cLinked exactInspect raw assertion
cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
47398fd0-6c5e-4625-9efd-de08c9ab7db2
product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp100w_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3cbaf763-195f-4b36-a450-719931b86650
cpe:2.3:o:zyxel:atp100w_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4cb974ec-859a-4b74-8a60-98a5406e8f43
cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
b8f79940-f737-4a71-9fac-1f99e0bce450
product-204c039ba605ff99a732d4aeb892002d51199a5a7289e8fc9a6195251cd09d02Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d68a36ff-8caf-401c-9f18-94f3a2405cf4
product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp200_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49ff3d01-c9aa-452c-a079-3180dc8db269
cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
84a41f09-4474-4abc-b2fa-92b17f63a7ca
cpe:2.3:o:zyxel:atp200_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8abed29d-8074-46ab-8a0f-759b0653691b
product-2aadc23472d0134ca1a46a96d237076a2f79c52ee591e309a631af2c09fe5858Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2818e8ac-ffee-4df9-bf3f-c75166c0e851
product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
8b7e5f75-5577-4511-a1f4-1bd142d60bd5
cpe:2.3:o:zyxel:atp500_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2a0e5b17-00e0-4cb0-9787-d6a8c8e1e0be
cpe:2.3:o:zyxel:atp500_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9801f3ab-4560-44aa-934f-0a6d31f46195
product-cea0f4a3423fb565b7fc5420cfee82db0edf528bf9235d8292671f6e8ae64fe8Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0b41f437-855b-4490-8011-df59887be6d5
product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
7728d2c4-0b0a-404e-92bc-aaa1a1987bfd
cpe:2.3:o:zyxel:atp700_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cf847a-a858-43a6-b35b-91455682e382
cpe:2.3:o:zyxel:atp700_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9be980d6-9d39-41b9-a35c-1879b72f4146
product-3d53771a3239415f970ae3ae39ad7aea35c319c755ea6e942a0f4add01901eb2Linked exactInspect raw assertion
cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
66b99746-0589-46e6-9cbd-f38619ad97dc
product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92Linked exactInspect raw assertions
cpe:2.3:o:zyxel:atp800_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eecc0fb9-ded8-4acf-a627-0537f3ee8c65
cpe:2.3:o:zyxel:atp800_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba1c872c-9192-410d-86f1-55cdf07de77c
cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.32; through excluding 5.36
- Match ID
791d6928-be82-4678-a8a4-39c9d9a1c684
product-0bd1e78fe15d29edcff9915f0cb954cead37cc7f3e9a331745ef4c5f1ac121a4Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg20-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7239c54f-ec9e-44b4-ae33-1d36e5448219
product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09eaLinked exactInspect raw assertions
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8fd54572-2c29-4d2e-b15a-de3a16d8e3ca
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bc69fab1-c862-470a-8cbf-bb8751485611
cpe:2.3:o:zyxel:usg20-vpn_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.30; through excluding 5.36
- Match ID
7079103c-ed92-40c3-af42-4689822a96e2
product-f9da0300b09cd9131de63e886e3f9279ed620453053ae48caacec872a6bcb053Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6bea412f-3da1-4e91-9c74-0666147dabce
product-41708052d4077bd8f08bf90364c85016ebd5c219f392954a84ed571d11e2981eLinked exactInspect raw assertions
cpe:2.3:o:zyxel:usg_20w-vpn_firmware:5.36:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5776089e-f9f4-4a0e-a169-fa1fc4dc6329
cpe:2.3:o:zyxel:usg_20w-vpn_firmware:5.36:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
107bb5b9-9c04-4c35-88ad-4d59ecd17778
product-dc2434e70cc224f2b01613a8d8b3e207cd628eccb56370b9f7b02bef542e8e53Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_40:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d84ddb81-de66-4427-8833-633b45a45a14
product-de3d811fd5332d78ee2526236da362690657e554712055ff114d2f22d95fb0b0Linked exactInspect raw assertions
cpe:2.3:o:zyxel:usg_40_firmware:4.73:patch1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa798b77-d4b4-4f21-a543-a6c5aad7878f
cpe:2.3:o:zyxel:usg_40_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.25; through excluding 4.73
- Match ID
24f44f62-be75-45de-9160-e807f6789be1
cpe:2.3:o:zyxel:usg_40_firmware:4.73:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97239f61-5715-476b-bd20-b40746aafe42
product-cc04a557ace4668ce5eb667c49a464ab6884df0cd1473b9ff517fdf939c0bb19Linked exactInspect raw assertion
cpe:2.3:h:zyxel:usg_40w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 20 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8f11f36c-60db-4d81-a320-53eee43758c1
Affected-product evidence
Accepted scope and product mapping
23 canonical links · 1 source-reported links
vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0b2bf582a5aa79942527606012ba4ef11a68ad9abca59a4abf071acaeb96106c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
26983fbe-354e-4a0c-96f8-b355fa2285eff2fea851-5fa0-4dc1-9484-ac49653c5ac7ffe61e4d-4ce6-4805-bc58-778d5eff6e61vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-0c7537a3c4e962c61695d9a69c09c71c4706711aff73126318bc69c88e8d810d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
63c84701-444e-4500-808e-17557e39c50465c360c7-74cc-4b70-9f1a-d0f234401c9cd418b47d-0bdc-44ce-8418-25e3ebacf597vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-326008e6d320d68bbeba0496f28a5df816c3b4b5fd083259f33968af444d8583
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
42f146e9-47a1-4fd9-938c-b6111c0c350cdcf02989-790c-41ee-9263-06ebe6c07c56de5ff22c-e507-472b-a2c2-dae9e75ab9c9vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-41708052d4077bd8f08bf90364c85016ebd5c219f392954a84ed571d11e2981e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3a8f7e41-d2f9-43e2-ba83-d703c29b8129cdcd0629-b74c-4087-802a-2392d10bea07vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-51aff2d0b03d80e26b46d437c992b29e60a2d3fc16c8471fd199c9d23383d177
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5297489c-3ffd-42f7-8a76-24f7752334068538896d-5bf7-4383-8ac9-5780ce2a1265ab080f04-cabb-4cc3-87a0-f89f7879aac9vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-5abdfb839c49688aabb3222f4bc5147ec7b4516467e598cdf06c89143c252874
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43fa322f-cc15-4d36-b9c8-c5866d5862cdfaa3e4f7-3126-4d26-a7ac-69a9b717dffevendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6082442a6083cd87efca032eced3b7c869d191d5abe797ca758b24a14219ab98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
050f7246-605a-47c7-bbd8-d4729ac7579263eb5d44-f4ca-4a86-9211-c6703715ad9bde639102-7756-4675-90de-785fa454b0bbvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-6e8453083842a704d3eef10ca166fe4982207762b43dbd869f4d6d6da51c6519
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5960dbc4-c5d8-475e-9eea-a1177bb71762620f8689-2086-40c2-8730-6bb4fa54b173c31986b3-5c7c-4e26-82fc-99f60ced65ffvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-73d8643b6be148d5a452006e63a97198060a54c941b1f1e4638cc41687b261d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
44bab761-46be-4c81-9971-94712e311422bed9b06e-617e-42ba-bc37-27efb325ce5ed4606f7a-cea1-4024-b807-814e37d3c260vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-750c77056e3509254876815ce6785adb86ce7c2ee089bdf23dab5a205a9686fc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07e06283-22b1-4532-bfc1-c9b6472ad99de69083ce-9935-4476-85b9-29b07f5a32fevendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-86f99bc9ab4d50c9559bddd263642e189da788ee7e254501649990d1e1771b98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
14b1a206-54e1-495e-a941-372e3820a3389e21e240-5a7d-4e36-a535-98183451e0f6d9bdb6da-616f-4a32-8e84-72e7151c7da7vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-936a8a7c943c7226136a60acef772ee4ce5ac143e5655c668b852f5b8d502342
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0f1ef0f0-a981-4d19-92eb-0623d86d3f282a0cd656-45f6-4a18-b25c-26a7ba969fb0c0b560be-c4f6-4074-a397-0d7e1d50a1c7vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-a61d6943c1bad48e17a6899eb15990b4a194af3c4c7456d58636c745ce6c0123
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
78f2c34d-1e02-4cfa-b8d3-5439c59ce29ac5aaf5ec-6f21-4886-bcef-67132a7f5533c7b0db2f-c2ee-454a-ad0e-512e3c85ed86vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-ba391e813d1ca8f48d81faa487ab68073af1b4115a2cc20d0969358c60e0f9ef
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12f7ed2a-66d3-489d-89b5-bdf441c15b35c253e312-9b34-4975-831f-4ea31cc1a0fce895f75b-49d1-4ee8-868d-3b3f2b670a3dvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-c0379851b411c8239197abf9661f20e966d7560c151b11c7647d2508bf2f7e92
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4202c39e-fe4d-46d4-899b-7db2549a7b4cdf4ae7be-9d56-4653-8f89-6247fb0085f6e1b42b72-5a53-4870-85b8-801ef6bfd417vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d262d95a9d2b47c5c7875f791f3c6fa9d5d2b48a0a40750bed16cd94cd692f89
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
35da7e63-c832-4154-8d2d-f5d726ac33327e88cda2-7281-4978-a3a8-4ec1c22be0178c0845eb-3a5c-48bc-8331-3417ede12fc9vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d49cc06bd1694635384653ea5099d635af0950d562113257ca2b986d5033461d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0e0a5690-d096-40c8-b07d-b95ac5e39ee8d157feba-ba46-40f3-af4d-d4ac6ee66991f4499113-0b97-4da6-817b-236e0d5901davendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-d781087797ffcbc50b6c52eb91f3e346a66c12189f2fe0f9f13d2c13ec28c3f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
19a48a7c-169f-4fc2-aacf-7900a97ffe1c3b174aa5-c24e-4672-bc83-05c243c13c08f24c5fe2-537d-40a2-bfbe-030dcb9b2822vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-de3d811fd5332d78ee2526236da362690657e554712055ff114d2f22d95fb0b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
22dd9aac-5444-4c46-9e6b-00ff98cb8f29273deb65-61b8-43ed-a724-7cdd0918f15f91e31c5f-8ce7-4360-b80d-688acf868485vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e09b599c8ada399dff2b8ab79fd7bbc40401bd2afbe161b152324fc7a13c2c40
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0bf4b2d0-3bcc-4afb-b1a3-fde0a8d1060b8ebeef45-3963-40a6-a39b-0d431ae3a757ab145fbc-aa3f-40da-8a46-8f6f5b20939cvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e4ca10df87762079f9b736c8c1995cdeb765fb4ad23b6ecc52f0bcca7fd863e0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0aab84f4-fb0b-4932-ad5a-9bf9b39a87f710a686ed-c1dd-4aaa-9d41-57d6425f1b041c7c7a37-3e1e-4058-b3c4-e8f2e4a4ab2d3532e7d7-fcd6-4ef2-a7d4-198c51584904vendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e5d0a9b1d297d36bfc243a7683973a65ca9f9b00f5fc83c43caf3713537e09ea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
27d688d4-2832-46c5-88a2-7b796f1154cfa6e8aa1b-3407-4b1d-a9bd-d6733b128128e91ce9a0-c701-4b8a-be08-7bc7676eb08bvendor-b18047daaf1c9692aefa2edb7182e0b8d93a7a346ff6d96ee9c363ca18b9f5cc · product-e80ae947ef2fbf604a1685f7dbf5e9c3fecc4edde631c371210a3a8519233fb1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18b24578-c1d6-4c41-9416-3900c595556961fb11db-978d-48a9-bad8-5073d5e7386aa884a191-9a6c-43a7-815d-ae1035c79823Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d728f79-f009-4be7-a255-f1c858d620fa13651312-db7d-4ebb-92d1-59ff80e0db97553d1a95-6bc3-4652-ba7f-6e965ca8fdfb8a495120-d47d-4f2a-bdd3-66a1f6499fd3ccb11158-71b2-4b6c-828a-c1a9591b78c3e0069529-2f78-4253-8041-86b107290003Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
Zyxel
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.