CVE-2023-28771
published 2023-04-25CVE-2023-28771: Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-21
Exploited in the wild
EPSS
99.28%
99.9th percentile
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp100w_firmware | >= 4.60 < 5.35 | 5.35 |
| zyxel | atp200_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp500_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp700_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp800_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp_series_firmware | — | — |
| zyxel | usg_flex_100_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_100w_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_200_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_500_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_50_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_50w_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_700_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_flex_series_firmware | — | — |
| zyxel | vpn1000_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | vpn100_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | vpn300_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | vpn50_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | vpn_series_firmware | — | — |
| zyxel | zywall_usg_100_firmware | — | — |
| zyxel | zywall_usg_100_firmware | >= 4.60 < 4.73 | 4.73 |
| zyxel | zywall_usg_310_firmware | — | — |
| zyxel | zywall_usg_310_firmware | >= 4.60 < 4.73 | 4.73 |
| zyxel | zywall_usg_series_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
XOR key 0x55 on 32-byte decryption key, then ChaCha20 decrypt (Dark.IoT config decryption)
- →CVE-2023-28771 is exploited via a crafted IKE packet sent over UDP port 500 targeting Zyxel firewall devices; monitor/block malformed IKE traffic on UDP/500 from untrusted sources. ↗
- →Post-exploitation payloads are exclusively MIPS architecture ELF binaries, dropped to /tmp with filenames like '.zw' and executed with the 'zywall' argument; hunt for MIPS ELF drops in /tmp on Linux-based firewall devices. ↗
- →Dark.IoT variant can be identified by the hardcoded string 'pte8cjbdwrmn57g4i6qual20s1k3vfoh' and its use of ChaCha20 config encryption with a 32-byte key XOR'd with 0x55. ↗
- →The Mirai variant (6/13 botnet) sends a hard-coded first packet value of 0x17b99063 followed by the victim's public IP to its C2; this byte pattern in C2 traffic is a strong detection signal. ↗
- →The Katana/Shinji botnet (6/26 sample) prefixes its initial C2 packet with 'TCP Connect' and uses C2 domain djk38zbdhqpdlshfb[.]shinji[.]app; monitor for this string in outbound TCP session initiation. ↗
- →The Katana/Shinji botnet checks execution path against '/lib', '/sbin/', and '/usr/' and reads '/proc/self/maps'; anomalous reads of /proc/self/maps by network-facing processes may indicate active botnet execution. ↗
- →Dark.IoT C2 domains use OpenNIC TLDs (.lib, .geek, .libre); DNS queries for these TLDs from IoT/firewall devices are a strong indicator of Dark.IoT infection. ↗
- →All 244 exploit-source IPs observed by GreyNoise on June 16 were classified malicious and geolocated to Verizon Business infrastructure; because the exploit is UDP-based, IP spoofing is possible — do not rely solely on source IP for attribution. ↗
- ·The exploit targets the IKE packet decoder on UDP/500; Zyxel devices with this port unnecessarily exposed to the internet are at highest risk. Reducing UDP/500 exposure where IKE/VPN is not required is a key mitigation. ↗
- ·The campaign updated its infrastructure and payloads within days (observed changes from 6/7 to 6/8–6/27), meaning static IP/domain blocklists will have limited longevity; behavioral detection is preferred. ↗
- ·The Mirai variant (6/13) uses an index-based XOR decoding scheme with multiple keys for its .rodata configuration; static string extraction will not reveal C2 servers without implementing the decoding logic. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Zyxel Multiple Firewalls OS Command Injection Vulnerability
cisa·2023-05-31·CVSS 9.8
CVE-2023-28771 [CRITICAL] CWE-78 Zyxel Multiple Firewalls OS Command Injection Vulnerability
Vulnerability: Zyxel Multiple Firewalls OS Command Injection Vulnerability
Affected: Zyxel Multiple Firewalls
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-28771
Remediation Due Date: 2023-06-21
GHSA
GHSA-3xvp-8qg2-x43w: Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4
ghsa_unreviewed·2023-04-25
CVE-2023-28771 [CRITICAL] CWE-78 GHSA-3xvp-8qg2-x43w: Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
VulnCheck
Zyxel Multiple Firewalls OS Command Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-28771 [CRITICAL] CWE-78 Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Affected: Zyxel Multiple Firewalls
Required Action: Apply updates per vendor instructions.
Exploitation References: https://cyberplace.social/@GossiTheDog/110428080243894672; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.fortinet.com/blog/threat-research/ddos-botnets-target-zyxel-vulnerability-cve-2023-28771; https://information.rapid7.com/rs/411-NAK-970/images/Rapid7-2023-Mid-Year-Threat-Review.pdf; https://sektorcert.dk/wp-content/uploads/2023/11/SektorCERT-
Suricata
ET EXPLOIT Zyxel ZyWALL/USG OS Command Injection (CVE-2023-28771)
suricata·2025-06-20·CVSS 9.8
CVE-2023-28771 [CRITICAL] ET EXPLOIT Zyxel ZyWALL/USG OS Command Injection (CVE-2023-28771)
ET EXPLOIT Zyxel ZyWALL/USG OS Command Injection (CVE-2023-28771)
Rule: alert udp any any -> $HOME_NET 500 (msg:"ET EXPLOIT Zyxel ZyWALL/USG OS Command Injection (CVE-2023-28771)"; flow:stateless,to_server; content:"|29 20 22 08|"; fast_pattern; offset:16; depth:4; content:"|28 00|"; distance:0; content:"|00 0e|"; distance:4; within:2; pcre:"/^.*?[\x3b\x24\x27\x60\x7c]/R"; reference:url,www.fortinet.com/blog/threat-research/ddos-botnets-target-zyxel-vulnerability-cve-2023-28771; reference:cve,2023-28771; classtype:web-application-attack; sid:2063094; rev:1; metadata:affected_product Zyxel, attack_target Server, created_at 2025_06_20, cve CVE_2023_28771, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2025_06_20, mitre_tactic_
Nuclei
Unauthenticated ZyXEL USG ZTP - Detect
nuclei·CVSS 9.8
CVE-2023-28771 [CRITICAL] Unauthenticated ZyXEL USG ZTP - Detect
Unauthenticated ZyXEL USG ZTP - Detect
Make a ZyXEL USG with ZTP support, pre CVE-2023-28771 patch, do a DNS lookup by asking it to make an ICMP request.
This template can be used to detect hosts potentially vulnerable to CVE-2023-28771, CVE-2022-30525, and other issues, without actually exploiting the vulnerability.
Template:
id: unauth-ztp-ping
info:
name: Unauthenticated ZyXEL USG ZTP - Detect
author: dmartyn
severity: high
description: |
Make a ZyXEL USG with ZTP support, pre CVE-2023-28771 patch, do a DNS lookup by asking it to make an ICMP request.
This template can be used to detect hosts potentially vulnerable to CVE-2023-28771, CVE-2022-30525, and other issues, without actually exploiting the vulnerability.
reference:
- https://www.fullspectrum.dev/the-hunt-for-cve-2023-28771-
Metasploit
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
metasploit
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
This module exploits a remote unauthenticated command injection vulnerability in the Internet Key Exchange (IKE) packet decoder over UDP port 500 on the WAN interface of several Zyxel devices. The affected devices are as follows: ATP (Firmware version 4.60 to 5.35 inclusive), USG FLEX (Firmware version 4.60 to 5.35 inclusive), VPN (Firmware version 4.60 to 5.35 inclusive), and ZyWALL/USG (Firmware version 4.60 to 4.73 inclusive). The affected devices are vulnerable in a default configuration and command execution is with root privileges.
arXiv
From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union
arxiv_fulltext·2025-10-06
From Cyber Security Incident Management to Cyber Security Crisis Management in the European Union
From Cyber Security Incident Management to
Cyber Security Crisis Management in the European Union
[sdu]Jukka Ruohonencor
[email protected]
[utu]Kalle Rindell
[uot]Simone Busetti
[cor]Corresponding author.
[sdu]University of Southern Denmark, Denmark
[utu]University of Turku, Finland
[uot]University of Teramo, Italy
## Abstract
Incident management is a classical topic in cyber security. Recently, the
European Union (EU) has started to consider also the relation between cyber
security incidents and cyber security crises. These considerations and
preparations, including those specified in the EU's new cyber security laws,
constitute the paper's topic. According to an analysis of the laws and
associated policy documents, (i) cyber security crises are equated in the EU to
large-scale cyber sec
Greynoiseio
GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771
blogs_greynoiseio·2025-06-16·CVSS 9.8
[CRITICAL] GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Fortinet
Botnets Continue Exploiting CVE-2023-1389 for Wide-Scale Spread | FortiGuard Labs
blogs_fortinet·2024-04-16·CVSS 8.8
CVE-2023-1389 [HIGH] Botnets Continue Exploiting CVE-2023-1389 for Wide-Scale Spread | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Botnets Continue Exploiting CVE-2023-1389 for Wide-Scale Spread
Infection - CVE-2023-1389
AGoent
Gafgyt Variant
Moobot
Mirai Variant
Miori
Condi
Conclusion
Fortinet Protections
IOCs
C2
URLs
Files
By Cara Lin and Vincent Li | April 16, 2024
Affected Platforms: TP-Link Archer AX21 (AX1800) Version 1.1.4 Build 20230219 or prior
Impacted Users: Any organization
Impact: Remote attackers gain control of the vulnerable systems
Severity Level: High
Last year, a command injection vulnerability, CVE-2023-1389, was disclosed and a fix developed for the web management interface of the TP-Link Archer AX21 (AX1800). FortiGuard Labs has developed an IPS signature to tackle this issue. Recently, we observed multiple attacks focusing on this year-old vulnerability, spotl
Checkpoint
13th November – Threat Intelligence Report
blogs_checkpoint·2023-11-13
CVE-2023-38547 13th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th November, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
US unit of China’s largest bank, the Industrial and Commercial Bank of China (ICBC), has suffered a ransomware attack that disrupted some of its financial services systems, reportedly affecting liquidity in US Treasuries. LockBit ransomware gang is reportedly behind the attack.
Check Point Threat Emulation and Harmony
Fortinet
OriginBotnet Spreads via Malicious Word Document | FortiGuard Labs
blogs_fortinet·2023-09-11
OriginBotnet Spreads via Malicious Word Document | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
OriginBotnet Spreads via Malicious Word Document
By Cara Lin | September 11, 2023
Affected platforms: Windows
Impacted parties: Any organization
Impact: Remote attackers steal credentials, sensitive information, and cryptocurrency
Severity level: Critical
In August, FortiGuard Labs obtained a Word document containing a malicious URL designed to entice victims to download a malware loader. This loader employs a binary padding evasion strategy that adds null bytes to increase the file's size to 400 MB. The payloads of this loader include OriginBotnet for keylogging and password recovery, RedLine Clipper for cryptocurrency theft, and AgentTesla for harvesting sensitive information. Figure 1 illustrates the comprehensive attack flow.
In this blog, we examin
Fortinet
DDoS Botnets Target Zyxel Vulnerability CVE-2023-28771 | FortiGuard Labs
blogs_fortinet·2023-07-19·CVSS 9.8
CVE-2023-28771 [CRITICAL] DDoS Botnets Target Zyxel Vulnerability CVE-2023-28771 | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
DDoS Botnets Target Zyxel Vulnerability CVE-2023-28771
By Cara Lin | July 19, 2023
Affected platforms: Linux
Impacted parties: Any organization
Impact: Remote attackers gain control of the vulnerable systems
Severity level: Critical
In June 2023, FortiGuard Labs detected the propagation of several DDoS botnets exploiting the Zyxel vulnerability (CVE-2023-28771). This vulnerability is characterized by a command injection flaw affecting multiple firewall models that could potentially allow an unauthorized attacker to execute arbitrary code by sending a specifically crafted packet to the targeted device. The severity of this flaw, rated 9.8 on the CVSS scoring system, was reported by researchers from TRAPA Security. Zyxel released a security advisory regard
Fortinet
MOVEit Transfer Critical Vulnerability (CVE-2023-34362) Exploited as a 0-day | FortiGuard Labs
blogs_fortinet·2023-06-08·CVSS 9.8
CVE-2023-34362 [CRITICAL] MOVEit Transfer Critical Vulnerability (CVE-2023-34362) Exploited as a 0-day | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
MOVEit Transfer Critical Vulnerability (CVE-2023-34362) Exploited as a 0-day
By James Slaughter, Fred Gutierrez, and Shunichi Imano | June 08, 2023
Affected Platforms: All unpatched MOVEit Transfer versions running a SQL database
Impacted Users: Any organization that uses a vulnerable version of MOVEit Transfer
Impact: Remote attackers can install a backdoor and exfiltrate data
Severity Level: High
FortiGuard Labs is aware of a critical zero-day SQL injection vulnerability in the MOVEit Secure Managed File Transfer software (CVE-2023-34362) allegedly exploited by the Cl0p ransomware threat actor. High-profile government, finance, media, aviation, and healthcare organizations have reportedly been affected, with data exfiltrated and stolen.
Due to its seve
Fortinet
Rise of One More Mirai Worm Variant
blogs_fortinet·2017-12-12·CVSS 9.8
[CRITICAL] Rise of One More Mirai Worm Variant
FORTIGUARD LABS THREAT RESEARCH
Rise of One More Mirai Worm Variant
By David Maciejak | December 12, 2017
Not long after a new strain of the Akuma malware was discovered targeting ZyXEL devices with a new series of login/password attacks, FortiGuard Labs last week also began detecting strange scanning activities on uncommon TCP ports 52869 and 37215. We and other threat research teams quickly began to suspect that these were tied together, and that there was a new botnet out there.
With some focused research, the new Satori botnet, or “Okiru” – as it was named by its malevolent author – came to light. Okiru is a Japanese word that can be translated to “to get up” or “to rise”. Okiru first appeared on our radar at the end of October 2017, but during the first week of December it signific
http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.htmlhttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewallshttp://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.htmlhttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewallshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28771
2023-04-25
Published
2023-05-31
Added to CISA KEV
Exploited in the wild