Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2023-28771

Zyxel | Multiple FirewallsAdded 2023-05-31Remediation Deadline 2023-06-21

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-78

References