Categories: Cyber Security News

Hackers Actively Exploit Zyxel RCE Vulnerability Through UDP Port

On June 16, 2025, GreyNoise detected a coordinated surge of exploit attempts targeting CVE-2023-28771, a critical remote code execution (RCE) vulnerability in Zyxel firewalls.

The activity involved 244 unique IP addresses targeting UDP port 500, with infrastructure linked to Verizon Business and patterns consistent with Mirai-based botnets.

This marks the first large-scale exploitation wave since the vulnerability was disclosed in April 2023.

Exploit Surge Details

Concentrated Attack Wave

  • Timing: Exploit attempts spiked on June 16, 2025, after minimal activity in preceding weeks.
  • IP Analysis: All 244 IPs were geolocated to the U.S. and registered to Verizon Business, though UDP spoofing complicates attribution.
  • Targets: Top destination countries included the U.S., U.K., Spain, Germany, and India.

Botnet Linkages

  • Payload Patterns: GreyNoise identified payload signatures matching Mirai variants, known for enslaving devices into distributed denial-of-service (DDoS) botnets.
  • Post-Exploitation Risks: Compromised devices could enable lateral movement, data exfiltration, or participation in DDoS campaigns.

Technical Analysis of CVE-2023-28771

Vulnerability Overview

  • CVSS Score: 9.8 (Critical).
  • Mechanism: Improper error handling in Zyxel’s IKEv2 packet decoder allows unauthenticated attackers to inject OS commands via crafted UDP/500 packets.
  • Affected Devices: Product LineVulnerable FirmwarePatch VersionATP SeriesZLD V4.60–V5.35ZLD V5.36USG FLEX SeriesZLD V4.60–V5.35ZLD V5.36ZyWALL/USG SeriesZLD V4.60–V4.73ZLD V4.73 Patch

Exploit Methodology

Sponsored
  • Attackers send malicious IKEv2 packets to UDP/500, bypassing authentication to execute commands as the root user.
  • Default configurations are vulnerable, requiring no VPN setup or administrative privileges.

Mitigation Strategies

Immediate Actions

  1. Patch Devices: Upgrade to ZLD V5.36 (ATP/USG FLEX/VPN) or ZLD V4.73 Patch 1 (ZyWALL/USG).
  2. Block Malicious IPs: GreyNoise recommends blocking the 244 flagged IPs despite spoofing risks.
  3. Restrict UDP/500 Exposure: Apply network ACLs to limit inbound traffic to trusted sources

Monitoring and Recovery

  • Detect Anomalies: Search for unusual processes, unexpected outbound connections, or sudden traffic spikes.
  • Incident Response: Isolate compromised devices, audit logs for IKEv2 anomalies, and perform forensic analysis.

Risk Factor Table

Metric Details
CVE ID CVE-2023-28771
CVSS v3.0 Score 9.8 (Critical)
Affected Products Zyxel ATP, USG FLEX, VPN, ZyWALL/USG
Exploit Availability Public exploits (Metasploit)
Active Exploitation Yes (Mirai botnet activity confirmed)

This incident underscores the persistent threat posed by unpatched network infrastructure.

Organizations using Zyxel devices must prioritize remediation to avoid becoming entry points for large-scale cyberattacks.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

The post Hackers Actively Exploit Zyxel RCE Vulnerability Through UDP Port appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Nintendo Direct to Show Off Final Trailer for The Super Mario Galaxy Movie Next Week

Nintendo has announced a Nintendo Direct revealing the final trailer for The Super Mario Galaxy…

2 minutes ago

Indie games are turning the act of looking into an art

Adriaan de Jongh and Sylvain Tegroeg did not necessarily set out to create a new…

37 minutes ago

A Look Back, March 6

50 Years Ago Florence merchants, irate over the “surprise” installation of 27 no-parking signs yesterday…

56 minutes ago

Photo: The path to education

The post Photo: The path to education appeared first on Daily Hampshire Gazette.

57 minutes ago

Gas line misalignment causes 6-month delay for Northampton’s Picture Main Street project

NORTHAMPTON — Picture Main Street, a project planned to remake the city’s downtown, has been delayed…

57 minutes ago

Records measure exposes more tension between lawmakers, auditor

BOSTON — Sen. Cindy Friedman banged the gavel multiple times, but it didn’t stop simmering…

57 minutes ago

This website uses cookies.