CVE-2023-28770: Zyxel DX5401-b0 Firmware

High severity, CVSS 7.5. EPSS: 57.8% chance of exploitation in the next 30 days.

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

Affected products

  • Zyxel DX5401-b0 Firmware: before 5.17\(abyo.1\)c0 (fixed in 5.17\(abyo.1\)c0)

Published 2023-04-27. Last modified 2026-06-17.