Zyxel Releases Security Updates
Security updates address vulnerabilities in Zyxel ATP, USG, and VPN products, including a command injection vulnerability
Summary
Security updates address vulnerabilities in Zyxel ATP, USG, and VPN products, including a command injection vulnerability
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Access Points:
- NAP203
- NAP303
- NAP353
- NWA110AX
- NWA1123-AC-PRO
- NWA1123ACv3
- NWA210AX
- NWA220AX-6E
- NWA50AX
- NWA50AX-PRO
- NWA5123-AC HD
- NWA90AX
- NWA90AX-PRO
- WAC500
- WAC500H
- WAC5302D-Sv2
- WAC6103D-I
- WAC6303D-S
- WAC6502D-E
- WAC6502D-S
- WAC6503D-S
- WAC6552D-S
- WAC6553D-E
- WAX510D
- WAX610D
- WAX620D-6E
- WAX630S
- WAX640S-6E
- WAX650S
- WAX655E
Threat details
Exploitation in the wild for CVE-2023-28771
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-28771 to their Known Exploited Vulnerability Catalog, an OS command injection vulnerability that could allow a remote, unauthenticated attacker to execute some OS commands by sending crafted packets to an affected system.
Introduction
Zyxel has released security updates to address vulnerabilities in a range of products and access points, including Zyxel VPN, ATP and USG. A Critical severity vulnerability affects ATP, USG FLEX, VPN, and ZyWALL/USG, which could allow an unauthenticated attacker to execute remote commands by sending maliciously crafted packets to an affected device.
Zyxel releases additional mitigation guidance for CVE-2023-28771
Zyxel has published additional guidance relating to vulnerability CVE-2023-28771 for temporary mitigation and precautionary purposes:
- Unless it is absolutely necessary for devices to be managed from the WAN side, HTTP/HTTPS services should be disabled from the WAN.
- If devices still need to be managed from the WAN side:
- Enable Policy Control and add rules to only allow access from trusted source IP addresses; and
- Enable GeoIP filtering to only allow access from trusted locations.
- If use of the IPSec VPN function is not required, disable the UDP Port 500 and Port 4500.
Threat updates
| Date | Update |
|---|---|
| 5 Jun 2023 |
Zyxel releases additional mitigation guidance for CVE-2023-28771
This cyber alert has been updated to reflect this change. |
| 1 Jun 2023 |
Exploitation in the wild for CVE-2023-28771
This cyber alert has been updated to reflect this change. |
Remediation advice
Affected organisations are encouraged to review Zyxel's security advisories and apply the relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Zyxel security advisory for XSS vulnerability and post-authentication command injection vulnerability in firewalls
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls |
| Patch |
Zyxel security advisory for OS command injection vulnerability of firewalls
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls |
| Patch |
Zyxel security advisory for multiple vulnerabilities of firewalls and access points
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 5 June 2023 1:59 pm