- May 4, 2019
- 827
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw in Zyxel gear to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2023-28771 (CVSS score: 9.8), the issue relates to a command injection flaw impacting different firewall models that could enable an unauthenticated attacker to execute arbitrary code by sending a specially crafted packet to the device.

Active Mirai Botnet Variant Exploiting Zyxel Devices for DDoS Attacks
U.S. Cybersecurity Agency raises alarm over critical flaw in Zyxel gear! Active exploitation detected.
