Zyxel Multiple Firewalls OS Command Injection Vulnerability
Zyxel · Multiple Firewalls
Date added (CISA)
2023-05-31
Remediation due
2023-06-21
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.