peter bassill · operator
$ cve CVE-2023-28769 JSON

CVE-2023-28769

9.8
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.42% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2023-04-27
Last modified2026-06-17

Affected (2)

VendorProduct
zyxeldx5401-b0
zyxeldx5401-b0 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD