CISA Known Exploited Vulnerability

CVE-2023-28771

Zyxel · Multiple Firewalls

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Unknown

CISA description

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Required action

Apply updates per vendor instructions.