May 31, 2023 · Applied Cybernetics Group
CVE-2023-28771 — Zyxel Multiple Firewalls
Zyxel Multiple Firewalls OS Command Injection Vulnerability
- Added to KEV
2023-05-31- Federal due date
2023-06-21- Vendor
- Zyxel
- Product
- Multiple Firewalls
- EPSS
- 100.0th percentile (score 0.943, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-28771
CISA short description
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Required action
Apply updates per vendor instructions.