Zyxel ZyWALL Command Injection (CVE-2023-28771)

Related Vulnerabilities: CVE-2023-28771  

Check Point Reference: CPAI-2023-0356 Date Published: 6 Jun 2023 Severity: Critical Last Updated: Wednesday 13 December, 2023 Source: Industry Reference:CVE-2023-28771
Protection Provided by:

Security Gateway
R81, R80

Who is Vulnerable? Zyxel ZyWALL USG firmware version 4.60 prior to 4.73
Zyxel ZyWALL VPN firmware version 4.60 prior to 5.35
Zyxel ZyWALL USG FLEX firmware version 4.60 prior to 5.35
Zyxel ZyWALL ATP firmware version 4.60 prior to 5.35 Vulnerability Description A command injection vulnerability exists in Zyxel ZyWALL. Successful exploitation of this vulnerability would allow remote attackers to execute arbitrary OS commands in the effected system.