boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-28771

Zyxel Multiple Firewalls
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9928   99.9   YES
AFFECTED
  Product                     Versions             Fixed
  ZyWALL/USG series firmware  4.60 through 4.73 –  —
  VPN series firmware         4.60 through 5.35 –  —
  USG FLEX series firmware    4.60 through 5.35 –  —
  ATP series firmware         4.60 through 5.35 –  —
TIMELINE
  Mar 23  Reserved by Zyxel
  Apr 25  Published (CNA: Zyxel)
  May 31  Added to CISA KEV, remediation due 2023-06-21
CWE-78 · CNA: Zyxel · CVSS v3.1 · 3 references · KEV due June 21, 2023

Description

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 23, 2023ReservedReserved by Zyxel
April 25, 2023PublishedPublished (CNA: Zyxel)
May 31, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-06-21

Affected

Affected products and packages — 4 rows
VendorProduct / PackageEcosystemVersion introducedFixed
ZyxelZyWALL/USG series firmware—4.60 through 4.73—
ZyxelVPN series firmware—4.60 through 5.35—
ZyxelUSG FLEX series firmware—4.60 through 5.35—
ZyxelATP series firmware—4.60 through 5.35—

Weaknesses

CWE-78

References (3)

Related

Authoritative record: CVE-2023-28771 at cve.org

Vendors: zyxel

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-28771 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.