CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-05-31. EPSS: 99.3% chance of exploitation in the next 30 days.
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Affected products
- Zyxel ATP100 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel ATP100W Firmware: from 4.60, before 5.35 (fixed in 5.35)
- Zyxel ATP200 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel ATP500 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel ATP700 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel ATP800 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 100 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 100w Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 200 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 500 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 50 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 50w Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Usg Flex 700 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel VPN1000 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel VPN100 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel VPN300 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel VPN50 Firmware: from 4.60, before 5.36 (fixed in 5.36)
- Zyxel Zywall Usg 100 Firmware: from 4.60, before 4.73 (fixed in 4.73); version 4.73 only
- Zyxel Zywall Usg 310 Firmware: from 4.60, before 4.73 (fixed in 4.73); version 4.73 only
Published 2023-04-25. Last modified 2026-06-17.