TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

GreyNoise Observes Exploit Attempts Targeting Zyxel CVE-2023-28771

2025-06-16 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
91%
"greynoise observes exploit attempts targeting zyxel cve - 2023 - 28771 on june 16, greynoise observed exploit attempts targeting cve - 2023 - 28771 — a remote code execution vulnerability affecting zyxel internet key exchange ( ike ) packet decoders over udp port 500. key stats -…"
T1190Exploit Public-Facing Application
35%
"exposed zyxel devices are patched for cve - 2023 - 28771. - monitor for post - exploitation activity : exploit attempts may lead to botnet enlistment or additional compromise. monitor affected devices for anomalies. - limit unnecessary ike / udp port 500 exposure : apply network …"

Summary

‍On June 16, GreyNoise observed exploit attempts targeting CVE-2023-28771 — a remote code execution vulnerability affecting Zyxel Internet Key Exchange (IKE) packet decoders over UDP port 500.