On June 16, 2025, GreyNoise detected a coordinated surge of exploit attempts targeting CVE-2023-28771, a critical remote code execution (RCE) vulnerability in Zyxel firewalls.
The activity involved 244 unique IP addresses targeting UDP port 500, with infrastructure linked to Verizon Business and patterns consistent with Mirai-based botnets.
This marks the first large-scale exploitation wave since the vulnerability was disclosed in April 2023.
Concentrated Attack Wave
Botnet Linkages
Vulnerability Overview
Exploit Methodology
root user.Immediate Actions
Monitoring and Recovery
| Metric | Details |
|---|---|
| CVE ID | CVE-2023-28771 |
| CVSS v3.0 Score | 9.8 (Critical) |
| Affected Products | Zyxel ATP, USG FLEX, VPN, ZyWALL/USG |
| Exploit Availability | Public exploits (Metasploit) |
| Active Exploitation | Yes (Mirai botnet activity confirmed) |
This incident underscores the persistent threat posed by unpatched network infrastructure.
Organizations using Zyxel devices must prioritize remediation to avoid becoming entry points for large-scale cyberattacks.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post Hackers Actively Exploit Zyxel RCE Vulnerability Through UDP Port appeared first on Cyber Security News.
Nintendo has announced a Nintendo Direct revealing the final trailer for The Super Mario Galaxy…
Adriaan de Jongh and Sylvain Tegroeg did not necessarily set out to create a new…
50 Years Ago Florence merchants, irate over the “surprise” installation of 27 no-parking signs yesterday…
The post Photo: The path to education appeared first on Daily Hampshire Gazette.
NORTHAMPTON — Picture Main Street, a project planned to remake the city’s downtown, has been delayed…
BOSTON — Sen. Cindy Friedman banged the gavel multiple times, but it didn’t stop simmering…
This website uses cookies.