CVE-2023-28771 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 99.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-06-21.
Description
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.28% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2023-06-21 |
| Public exploit | none known |
| Published | 2023-04-25 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zyxel Multiple Firewalls OS Command Injection Vulnerability |
|---|---|
| Added | 2023-05-31 |
| Due | 2023-06-21 |
| Vendor / product | Zyxel / Multiple Firewalls |
| Ransomware use | none reported |
Affected (38)
| Vendor | Product |
|---|---|
| zyxel | atp100 |
| zyxel | atp100 firmware |
| zyxel | atp100w |
| zyxel | atp100w firmware |
| zyxel | atp200 |
| zyxel | atp200 firmware |
| zyxel | atp500 |
| zyxel | atp500 firmware |
| zyxel | atp700 |
| zyxel | atp700 firmware |
| zyxel | atp800 |
| zyxel | atp800 firmware |
| zyxel | usg flex 100 |
| zyxel | usg flex 100 firmware |
| zyxel | usg flex 100w |
| zyxel | usg flex 100w firmware |
| zyxel | usg flex 200 |
| zyxel | usg flex 200 firmware |
| zyxel | usg flex 50 |
| zyxel | usg flex 50 firmware |
| zyxel | usg flex 500 |
| zyxel | usg flex 500 firmware |
| zyxel | usg flex 50w |
| zyxel | usg flex 50w firmware |
| zyxel | usg flex 700 |
| zyxel | usg flex 700 firmware |
| zyxel | vpn100 |
| zyxel | vpn100 firmware |
| zyxel | vpn1000 |
| zyxel | vpn1000 firmware |
| zyxel | vpn300 |
| zyxel | vpn300 firmware |
| zyxel | vpn50 |
| zyxel | vpn50 firmware |
| zyxel | zywall usg 100 |
| zyxel | zywall usg 100 firmware |
| zyxel | zywall usg 310 |
| zyxel | zywall usg 310 firmware |
References
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.html
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.html
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28771
→ the Explorer · watch your stack · NVD