Critical Alert 4 Active Exploits Detected Today

CVE-2026-60137 WordPress Core SQL Injection Vulnerability →
CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability →
CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability →
CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2023-28771NVD

Vulnerability Summary

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Severity Level
CRITICAL(9.8)
Published Date
Apr 25, 2023
Last Modified
Oct 21, 2025
Exploitation Status
ACTIVE
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh