← Vulnerability feed

Vulnerability record · CVE-2023-28771 · published 25 April 2023

CVE-2023-28771: Zyxel firewall firmware OS command injection via crafted packets

Zyxel · Atp100 Firmware

Zyxel ZyWALL/USG, VPN, USG FLEX and ATP series firmware mishandle error messages, allowing OS command injection. An unauthenticated remote attacker can send crafted packets to execute commands on the device, making this a critical edge-device flaw.

9.8 CVSS 3.1 Critical CISA KEV since 31 May 2023 EPSS 99% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
19Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote OS command injection on internet-facing firewalls with a 9.8 CVSS, KEV listing and near-maximum EPSS makes this an urgent patch-first issue.

What it is

Zyxel ZyWALL/USG, VPN, USG FLEX and ATP series firmware mishandle error messages, allowing OS command injection. An unauthenticated remote attacker can send crafted packets to execute commands on the device, making this a critical edge-device flaw.

Impact

An attacker gains remote OS command execution on the firewall with no credentials, enabling full compromise of the device and any trust or routing it provides.

Attack surface

Reachable over the network via crafted packets to the affected device; the CVSS vector shows no privileges or user interaction required. The description does not name the specific service or port, though a public exploit reference points to the IKE packet decoder.

Exploitation

Listed in CISA KEV since 2023-05-31 with a required action deadline, and EPSS 30-day probability is 0.99284 (99.9th percentile). A public exploit reference is tagged Exploit, so active exploitation should be assumed.

What to do

  • Apply the vendor firmware updates in Zyxel's security advisory for the affected ZyWALL/USG, VPN, USG FLEX and ATP models.
  • If immediate patching is not possible, restrict internet exposure of the affected devices' management and IKE/VPN interfaces to trusted sources.
  • Monitor vendor and CISA guidance for the KEV due date and confirm remediation before 2023-06-21.
  • Inventory all listed models and firmware versions 4.60 through 4.73 (ZyWALL/USG) and 4.60 through 5.35 (VPN, USG FLEX, ATP) to find unpatched units.
  • Treat any internet-facing unpatched device as compromised and review it for unauthorized changes.

Detection

  • Hunt for unexpected outbound connections or command-and-control traffic originating from the firewall devices.
  • Review device logs for anomalous error-handling or IKE/VPN packet processing events around suspected exploitation.
  • Check for unauthorized configuration changes, new accounts or persistence on the affected appliances.
  • Correlate network telemetry for crafted packet patterns targeting the IKE service on exposed devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-28771 to the Known Exploited Vulnerabilities catalog on 31 May 2023 as "Zyxel Multiple Firewalls OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 June 2023.

Affected products

19 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28771 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-33009Zyxel firewall notification function buffer overflowA buffer overflow in the notification function of multiple Zyxel firewall and VPN firmware lines (ATP, USG FLEX, USG20(W)-VPN, VPN, ZyWALL/USG) allow…KEVEPSS 28%analysed9.8CVE-2023-33010Zyxel firewall ID processing buffer overflow allows unauthenticated RCEA classic buffer overflow (CWE-120) exists in the ID processing function of multiple Zyxel firewall firmware lines, including ATP, USG FLEX, USG20(W)…KEVEPSS 29%analysed9.8CVE-2022-30525Zyxel firewall CGI OS command injectionThe CGI program in multiple Zyxel firewall and VPN firmware lines fails to neutralize OS command syntax, allowing command injection. The flaw affects…KEVEPSS 100%analysed9.8CVE-2020-29583Zyxel USG and ATP firmware hard-coded admin credentialZyxel USG and ATP firmware version 4.60 ships an undocumented account (zyfwp) whose password is stored in cleartext in the firmware and cannot be cha…KEVEPSS 90%analysed9.8CVE-2020-9054ZyXEL NAS weblogin.cgi pre-auth command injectionZyXEL NAS devices running firmware 5.21 fail to sanitize the username parameter in the weblogin.cgi CGI executable, allowing OS command injection. Be…KEVEPSS 100%analysed9.8CVE-2022-0342Zyxel firewall CGI authentication bypass grants admin accessThe CGI program in multiple Zyxel firewall firmware lines (USG/ZyWALL, USG FLEX, ATP, VPN, NSG) fails to properly enforce authentication, allowing a …EPSS 95%analysed8.8CVE-2023-27991Zyxel atp200 firmware os command injection vulnerabilityThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f…EPSS 1.5%8.1CVE-2023-6764Zyxel atp100 firmware vulnerabilityA format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX s…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2023-28771), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.