Skip to main content

Zyxel Releases Security Updates

Security updates address vulnerabilities in Zyxel ATP, USG, and VPN products, including a command injection vulnerability

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address vulnerabilities in Zyxel ATP, USG, and VPN products, including a command injection vulnerability


The following platforms are also known to be affected:

Access Points:

  • NAP203         
  • NAP303         
  • NAP353         
  • NWA110AX  
  • NWA1123-AC-PRO  
  • NWA1123ACv3                    
  • NWA210AX  
  • NWA220AX-6E        
  • NWA50AX                
  • NWA50AX-PRO                   
  • NWA5123-AC HD    
  • NWA90AX    
  • NWA90AX-PRO       
  • WAC500        
  • WAC500H     
  • WAC5302D-Sv2       
  • WAC6103D-I
  • WAC6303D-S
  • WAC6502D-E
  • WAC6502D-S
  • WAC6503D-S
  • WAC6552D-S
  • WAC6553D-E           
  • WAX510D     
  • WAX610D     
  • WAX620D-6E
  • WAX630S     
  • WAX640S-6E
  • WAX650S     
  • WAX655E     

Threat details

Exploitation in the wild for CVE-2023-28771

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-28771 to their Known Exploited Vulnerability Catalog, an OS command injection vulnerability that could allow a remote, unauthenticated attacker to execute some OS commands by sending crafted packets to an affected system.


Introduction

Zyxel has released security updates to address vulnerabilities in a range of products and access points, including Zyxel VPN, ATP and USG. A Critical severity vulnerability affects ATP, USG FLEX, VPN, and ZyWALL/USG, which could allow an unauthenticated attacker to execute remote commands by sending maliciously crafted packets to an affected device.

Zyxel releases additional mitigation guidance for CVE-2023-28771

Zyxel has published additional guidance relating to vulnerability CVE-2023-28771 for temporary mitigation and precautionary purposes:

  1. Unless it is absolutely necessary for devices to be managed from the WAN side, HTTP/HTTPS services should be disabled from the WAN.
  2. If devices still need to be managed from the WAN side:
    • Enable Policy Control and add rules to only allow access from trusted source IP addresses; and
    • Enable GeoIP filtering to only allow access from trusted locations.
  3. If use of the IPSec VPN function is not required, disable the UDP Port 500 and Port 4500.

Threat updates

Date Update
5 Jun 2023 Zyxel releases additional mitigation guidance for CVE-2023-28771

This cyber alert has been updated to reflect this change.

1 Jun 2023 Exploitation in the wild for CVE-2023-28771

This cyber alert has been updated to reflect this change.


Remediation advice

Affected organisations are encouraged to review Zyxel's security advisories and apply the relevant updates.


Remediation steps

Type Step
Patch

Zyxel security advisory for XSS vulnerability and post-authentication command injection vulnerability in firewalls

  • ATP       
  • USG FLEX            
  • USG FLEX 50(W) / USG20(W)-VPN
  • VPN      

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls
Patch

Zyxel security advisory for OS command injection vulnerability of firewalls

  • ATP       
  • USG FLEX            
  • VPN
  • ZyWALL/USG

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
Patch

Zyxel security advisory for multiple vulnerabilities of firewalls and access points

  • ATP       
  • USG FLEX            
  • USG FLEX 50(W) / USG20(W)-VPN
  • VPN      
  • Access points listed above

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-of-firewalls-and-aps


CVE Vulnerabilities

Last edited: 5 June 2023 1:59 pm