Zyxel Multiple Firewalls OS Command Injection Vulnerability
Vendor: Zyxel
Product: Multiple Firewalls
Added: 2023-05-31
Due Date: 2023-06-21
Description:
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Required Action:
Apply updates per vendor instructions.
CWEs: