PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-28771 Zyxel CVE debrief

CVE-2023-28771 is a Zyxel Multiple Firewalls OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-05-31. The supplied corpus indicates this issue was known to be exploited and that the required defensive action is to apply updates per vendor instructions. A Zyxel security advisory referenced in the source notes describes the issue as a remote command injection vulnerability affecting firewalls.

Vendor
Zyxel
Product
Multiple Firewalls
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2023-05-31
Original CVE updated
2023-05-31
Advisory published
2023-05-31
Advisory updated
2023-05-31

Who should care

Security teams responsible for Zyxel firewalls, vulnerability management teams, SOC/incident response staff, and any organization that exposes Zyxel firewall management or related services.

Technical summary

The available source data identifies CVE-2023-28771 as an OS command injection vulnerability in Zyxel Multiple Firewalls. CISA’s KEV entry marks it as known exploited, with dateAdded 2023-05-31 and dueDate 2023-06-21. The corpus does not provide CVSS scoring or specific affected model/version details, so remediation should follow the Zyxel advisory and vendor update guidance.

Defensive priority

High. CISA KEV inclusion indicates known exploitation and an urgent need to patch or otherwise mitigate according to the vendor’s instructions.

Recommended defensive actions

  • Apply Zyxel updates or mitigations exactly as described in the vendor security advisory.
  • Inventory Zyxel firewall assets and verify which systems are affected.
  • Prioritize exposed or internet-reachable firewall instances for immediate remediation.
  • Review administrative and system logs for signs of unauthorized command execution or unexpected configuration changes.
  • Validate that patching or mitigation was completed before the CISA KEV due date, and continue monitoring for follow-on compromise.

Evidence notes

This debrief is based only on the supplied CISA KEV entry, the official CVE record link, and the NVD record link referenced in the corpus. The KEV metadata states: vendorProject Zyxel, product Multiple Firewalls, vulnerabilityName 'Zyxel Multiple Firewalls OS Command Injection Vulnerability,' dateAdded 2023-05-31, dueDate 2023-06-21, and requiredAction 'Apply updates per vendor instructions.' The KEV notes also reference Zyxel’s advisory titled 'security advisory for remote command injection vulnerability of firewalls.'

Sources and references

Verified primary and authoritative sources

  • CVE-2023-28771 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-28771

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-28771 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-28771

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.