PatchSiren cyber security CVE debrief
CVE-2023-28771 Zyxel CVE debrief
CVE-2023-28771 is a Zyxel Multiple Firewalls OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-05-31. The supplied corpus indicates this issue was known to be exploited and that the required defensive action is to apply updates per vendor instructions. A Zyxel security advisory referenced in the source notes describes the issue as a remote command injection vulnerability affecting firewalls.
- Vendor
- Zyxel
- Product
- Multiple Firewalls
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2023-05-31
- Original CVE updated
- 2023-05-31
- Advisory published
- 2023-05-31
- Advisory updated
- 2023-05-31
Who should care
Security teams responsible for Zyxel firewalls, vulnerability management teams, SOC/incident response staff, and any organization that exposes Zyxel firewall management or related services.
Technical summary
The available source data identifies CVE-2023-28771 as an OS command injection vulnerability in Zyxel Multiple Firewalls. CISA’s KEV entry marks it as known exploited, with dateAdded 2023-05-31 and dueDate 2023-06-21. The corpus does not provide CVSS scoring or specific affected model/version details, so remediation should follow the Zyxel advisory and vendor update guidance.
Defensive priority
High. CISA KEV inclusion indicates known exploitation and an urgent need to patch or otherwise mitigate according to the vendor’s instructions.
Recommended defensive actions
- Apply Zyxel updates or mitigations exactly as described in the vendor security advisory.
- Inventory Zyxel firewall assets and verify which systems are affected.
- Prioritize exposed or internet-reachable firewall instances for immediate remediation.
- Review administrative and system logs for signs of unauthorized command execution or unexpected configuration changes.
- Validate that patching or mitigation was completed before the CISA KEV due date, and continue monitoring for follow-on compromise.
Evidence notes
This debrief is based only on the supplied CISA KEV entry, the official CVE record link, and the NVD record link referenced in the corpus. The KEV metadata states: vendorProject Zyxel, product Multiple Firewalls, vulnerabilityName 'Zyxel Multiple Firewalls OS Command Injection Vulnerability,' dateAdded 2023-05-31, dueDate 2023-06-21, and requiredAction 'Apply updates per vendor instructions.' The KEV notes also reference Zyxel’s advisory titled 'security advisory for remote command injection vulnerability of firewalls.'
Sources and references
Verified primary and authoritative sources
-
CVE-2023-28771 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-28771
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-28771 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-28771
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.