CVE-2023-28770

HIGH EXPLOITED

Zyxel DX5401-B0 <V5.17(ABYO.1)C0 - Info Disclosure

Title source: llm

Description

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/zyxel_lfi_unauth_ssh_rce.rb

Scores

CVSS v3 7.5
EPSS 0.8369
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-11-28
CWE
CWE-200 CWE-203
Status published
Products (1)
zyxel/dx5401-b0_firmware < 5.17\(abyo.1\)c0
Published Apr 27, 2023
Tracked Since Feb 18, 2026