{"cveID":"CVE-2023-28771","vendorProject":"Zyxel","product":"Multiple Firewalls","vulnerabilityName":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","dateAdded":"2023-05-31","shortDescription":"Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-06-21","knownRansomwareCampaignUse":"Unknown","notes":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls;   https://nvd.nist.gov/vuln/detail/CVE-2023-28771","cwes":["CWE-78"],"year":2023,"state":"unmapped","stale_reasons":[],"mappings":[],"techniques":[],"mapping_types":[],"has_exploitation_technique":false,"mapping_attack_versions":[],"mapping_domains":[],"sigma_coverage":null,"sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}