ZeroHour

CVE-2023-28771

KEV PoC large

Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CISA: Zyxel Multiple Firewalls OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

What to do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

Affected
Zyxel ZyWALL/USG series firewallsfirmware 4.60 through 4.73
Zyxel VPN series firewallsfirmware 4.60 through 5.35
Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500)firmware 4.60 through 5.35
Zyxel ATP series firewalls (ATP100, ATP100W, ATP200, ATP500, ATP700, ATP800)firmware 4.60 through 5.35
Estimated exposure
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate — The affected ATP, USG FLEX, ZyWALL/USG, and VPN lines are mass-market SMB/enterprise perimeter firewalls commonly deployed with IKE/VPN exposed to the internet, and the source data contains no install or scan counts, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

CISA Known Exploited Vulnerability
Affected
Zyxel Multiple Firewalls
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
atp100 firmware, atp100w firmware, atp200 firmware, atp500 firmware, atp700 firmware, atp800 firmware, usg flex 100 firmware, usg flex 100w firmware, usg flex 200 firmware, usg flex 50 firmware, usg flex 500 firmware, usg flex 50w firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news