CVE-2023-28771
Zyxel Multiple Firewalls OS Command Injection Vulnerability
⚠ KEVEPSS 99.3%
Description
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
How to fix CVE-2023-28771
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2023-28771 being exploited?
Yes — CVE-2023-28771 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.