kevmap

Coverage › CVE-2023-28771

CVE-2023-28771 Unmapped

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Vendor / product
Zyxel — Multiple Firewalls
Description (CISA)
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Added to KEV
2023-05-31
Due date
2023-06-21
Required action
Apply updates per vendor instructions.
Known ransomware use
Unknown
CWE
CWE-78
CISA notes
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
https://nvd.nist.gov/vuln/detail/CVE-2023-28771
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2023-28771. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-78) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.