Zyxel Vulnerabilities
ID: e01f45c9-bd3a-54e2-9c64-afa96f72c2d4
STIX ID: report--e01f45c9-bd3a-54e2-9c64-afa96f72c2d4
Feed Name: Censys Blog
This report documents CVE-2023-28771, an OS command injection in Zyxel devices triggered during IKEv2 notify message processing that allows remote code execution; Rapid7 produced a scriptable exploit and as of May 25, 2023 the vulnerability is reported to be mass-exploited by the Mirai botnet. The authors enumerate roughly 24,457 Zyxel devices (about 21,210 running IKE) exposed on the internet, provide Censys queries and an ISP/ASN breakdown (notably concentrated in Europe), and describe the insecure logging implementation that introduces the command injection risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
