CVE-2023-28769

CRITICAL EXPLOITED

Zyxel DX5401-B0 Firmware < 5.17(ABYO.1)C0 - Unauthenticated Buffer Overflow in libclinkc.so

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-28769 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit, including a Metasploit module exploits/linux/misc/zyxel_multiple_devices_zhttp_lan_rce.

AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in the zhttpd binary on multiple Zyxel devices (CVE-2023-28769) to achieve unauthenticated remote code execution as root. It leverages a crafted URL to trigger the overflow and execute arbitrary commands via a reverse shell payload.

Description

The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

Exploits (1)

metasploit WORKING POC GOOD
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/zyxel_multiple_devices_zhttp_lan_rce.rb

This Metasploit module exploits a buffer overflow in the zhttpd binary on multiple Zyxel devices (CVE-2023-28769) to achieve unauthenticated remote code execution as root. It leverages a crafted URL to trigger the overflow and execute arbitrary commands via a reverse shell payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zyxel routers and CPE devices (zhttpd binary)
No auth needed
Prerequisites: Network access to the zhttp webserver on port 80 · LAN IP address of the attacker's machine for payload hosting
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7219
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2024-11-01
CWE
CWE-120
Status published
Products (1)
zyxel/dx5401-b0_firmware < 5.17\(abyo.1\)c0
Published Apr 27, 2023
Tracked Since Feb 18, 2026