LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 31, 2023
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Jun 21, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-28771 to its Known Exploited Vulnerabilities catalog on May 31, 2023, with a federal patch deadline of Jun 21, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

CVE-2023-28771 is an OS command injection vulnerability affecting multiple Zyxel firewalls, including ATP, USG FLEX, VPN, and ZyWALL/USG models. It stems from improper error message handling that can let an unauthenticated attacker execute operating system commands remotely by sending crafted packets to an affected device. This matters because these appliances often sit at the network edge; successful exploitation can give an attacker a foothold to pivot, alter security policy, or move laterally into internal systems.

Defenders should treat perimeter firewalls as high-value targets and confirm exposure against the vendor advisory rather than relying on incomplete public details.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In this case, the CISA summary states that improper error message handling on the listed Zyxel firewalls allows an unauthenticated remote attacker to execute OS commands by sending crafted packets to an affected device. Command injection of this class typically occurs when user-controlled input reaches a system shell or command interpreter without adequate sanitization or escaping; here the trigger is tied to error-message processing rather than a more common web parameter. An attacker who can reach the vulnerable service can therefore inject and run arbitrary commands with the privileges of the affected process. Exact packet formats, protocol details, or required conditions are not provided in the available facts and must be confirmed against the vendor advisory; do not assume public proof-of-concept code is complete or safe to test in production.

Am I affected? How to find it in your systems

The vulnerability impacts Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls. These devices commonly appear as edge or branch firewalls, VPN gateways, or unified threat management appliances in enterprise and SMB environments. Inventory steps include:

If you cannot determine the precise version or configuration, treat the device as potentially affected until the vendor advisory confirms otherwise.

How to remediate

The primary remediation is to apply the updates published by Zyxel according to the vendor instructions, as directed by CISA. Download firmware only from official Zyxel channels, verify integrity if hashes are supplied, and follow the vendor’s upgrade procedure for each model family (ATP, USG FLEX, VPN, ZyWALL/USG). After patching:

For this class of OS command injection, also review any custom scripts or external integrations that interact with the firewall’s error-handling paths and ensure they do not re-introduce unsanitized input.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution flaws on perimeter devices can lead to full compromise and subsequent data exposure. Known ransomware use of this specific CVE is not documented in the available facts, yet any successful command execution still warrants a thorough incident review. Check device logs for signs of unauthorized access, rotate credentials that may have been present on the appliance, and examine connected systems for lateral movement. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZyxel · Multiple Firewalls
WeaknessCWE-78
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedApr 25, 2023
Added to CISA KEVMay 31, 2023
Federal patch deadlineJun 21, 2023
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities