CVE-2023-28769: Zyxel DX5401-b0 Firmware

Critical severity, CVSS 9.8. EPSS: 5.4% chance of exploitation in the next 30 days.

The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

Affected products

  • Zyxel DX5401-b0 Firmware: before 5.17\(abyo.1\)c0 (fixed in 5.17\(abyo.1\)c0)

Published 2023-04-27. Last modified 2026-06-17.