Junglewise Threat Intelligence

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

CVE-2023-28771 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-05-31

Technologies: Zyxel Multiple Firewalls, Zyxel Firewalls. Vendors: Zyxel.

Executive brief

Improper error message handling in multiple Zyxel firewall series allows an unauthenticated remote attacker to execute OS commands by sending crafted packets to the device. The vulnerability stems from a flaw in the IKE packet decoder.

Affected products

  • Zyxel ATP series firmware 4.60 through 5.35
  • Zyxel USG FLEX series firmware 4.60 through 5.35
  • Zyxel VPN series firmware 4.60 through 5.35
  • Zyxel ZyWALL/USG series firmware 4.60 through 4.73

Timeline

  • 2023-05-31: disclosed: Vulnerability published and added to CISA KEV catalog
  • 2023-05-31: kev added
  • 2023-05-31: exploited: Reported as exploited in the wild at time of publication

Related threats