Vulnerability record · CVE-2023-28771 · published 25 April 2023
CVE-2023-28771: Zyxel firewall firmware OS command injection via crafted packets
Zyxel · Atp100 Firmware
Zyxel ZyWALL/USG, VPN, USG FLEX and ATP series firmware mishandle error messages, allowing OS command injection. An unauthenticated remote attacker can send crafted packets to execute commands on the device, making this a critical edge-device flaw.
Description
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote OS command injection on internet-facing firewalls with a 9.8 CVSS, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.
What it is
Zyxel ZyWALL/USG, VPN, USG FLEX and ATP series firmware mishandle error messages, allowing OS command injection. An unauthenticated remote attacker can send crafted packets to execute commands on the device, making this a critical edge-device flaw.
Impact
An attacker gains remote OS command execution on the firewall with no credentials, enabling full compromise of the device and any trust or routing it provides.
Attack surface
Reachable over the network via crafted packets to the affected device; the CVSS vector shows no privileges or user interaction required. The description does not name the specific service or port, though a public exploit reference points to the IKE packet decoder.
Exploitation
Listed in CISA KEV since 2023-05-31 with a required action deadline, and EPSS 30-day probability is 0.99284 (99.9th percentile). A public exploit reference is tagged Exploit, so active exploitation should be assumed.
What to do
- Apply the vendor firmware updates in Zyxel's security advisory for the affected ZyWALL/USG, VPN, USG FLEX and ATP models.
- If immediate patching is not possible, restrict internet exposure of the affected devices' management and IKE/VPN interfaces to trusted sources.
- Monitor vendor and CISA guidance for the KEV due date and confirm remediation before 2023-06-21.
- Inventory all listed models and firmware versions 4.60 through 4.73 (ZyWALL/USG) and 4.60 through 5.35 (VPN, USG FLEX, ATP) to find unpatched units.
- Treat any internet-facing unpatched device as compromised and review it for unauthorized changes.
Detection
- Hunt for unexpected outbound connections or command-and-control traffic originating from the firewall devices.
- Review device logs for anomalous error-handling or IKE/VPN packet processing events around suspected exploitation.
- Check for unauthorized configuration changes, new accounts or persistence on the affected appliances.
- Correlate network telemetry for crafted packet patterns targeting the IKE service on exposed devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-28771 to the Known Exploited Vulnerabilities catalog on 31 May 2023 as "Zyxel Multiple Firewalls OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 June 2023.
Affected products
19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-28771 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28771), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.