LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2023-28771

CVE-2023-28771

Zyxel Multiple Firewalls OS Command Injection Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2023-05-31. Federal remediation due 2023-06-21.
Required action: Apply updates per vendor instructions.

Summary

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Zyxel atp100 firmwareZyxel atp100Zyxel atp100w firmwareZyxel atp100wZyxel atp200 firmwareZyxel atp200Zyxel atp500 firmwareZyxel atp500Zyxel atp700 firmwareZyxel atp700Zyxel atp800 firmwareZyxel atp800Zyxel usg flex 100 firmwareZyxel usg flex 100Zyxel usg flex 100w firmwareZyxel usg flex 100wZyxel usg flex 200 firmwareZyxel usg flex 200Zyxel usg flex 50 firmwareZyxel usg flex 50
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-27. Always verify against the vendor advisory before acting.

Scroll to Top