Threat and Patch Advisory

Zyxel CVE-2023-28771 – Command Injection

Improper error message handling in Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls creates a vulnerability that can be exploited by an unauthorized attacker. By sending manipulated packets to a targeted device, the attacker can remotely execute operating system commands.

Affected Products:

ATPZLD V4.60 to V5.35ZLD V5.36
USG FLEXZLD V4.60 to V5.35ZLD V5.36
VPNZLD V4.60 to V5.35ZLD V5.36
ZyWALL/USGZLD V4.60 to V4.73ZLD V4.73 Patch 1

Patches are available at the Zyxel website, click the Reference button