← KEV catalog
CISA known exploited vulnerability

CVE-2023-28771

Zyxel Multiple Firewalls OS Command Injection Vulnerability

SOURCE FACT

Zyxel · Multiple Firewalls

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Required action

Apply updates per vendor instructions.

CISA notes

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-28771

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?