CVE-2023-28770
HIGH EXPLOITEDZyxel DX5401-B0 <V5.17(ABYO.1)C0 - Info Disclosure
Title source: llmDescription
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zyxel_lfi_unauth_ssh_rce.rb
References (3)
Scores
CVSS v3
7.5
EPSS
0.8369
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2023-11-28
CWE
CWE-200
CWE-203
Status
published
Products (1)
zyxel/dx5401-b0_firmware
< 5.17\(abyo.1\)c0
Published
Apr 27, 2023
Tracked Since
Feb 18, 2026