Zyxel Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Zyxel products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
16
In CISA KEV
12
Beyond CISA KEV
4
Sensor Observed
2
Virtual Patch Available
1
Zyxel KEVs Added by Year
16 Zyxel KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-29972
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before... |
NAS326 firmware, NAS542 firmware | Confirmed | Not in CISA | 15 Jul 2026 |
|
CVE-2021-3297
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. |
NBG2105 | High | Not in CISA | 16 Sep 2025 |
|
CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before... |
NAS326 firmware, NAS542 firmware | High | Not in CISA | 26 Jun 2025 |
|
CVE-2020-29583
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account... |
USG devices | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-9054
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi |
NAS326, NAS520, NAS540, NAS542, NSA210, NSA220, NSA220+, NSA221, NSA310, NSA320, NSA320S, NSA325, NSA325v2 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware... |
USG FLEX 100(W) firmware, USG FLEX 200 firmware, USG FLEX 500 firmware, USG FLEX 700 firmware, ATP series firmware, VPN series firmware, USG FLEX 50(W) firmware, USG 20(W)-VPN firmware | Confirmed | In CISA | 16 May 2022 |
|
CVE-2023-28771
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG... |
ZyWALL/USG series firmware, VPN series firmware, USG FLEX series firmware, ATP series firmware | Confirmed | In CISA | 31 May 2023 |
|
CVE-2023-33010
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | Confirmed | In CISA | 05 Jun 2023 |
|
CVE-2023-33009
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | Confirmed | In CISA | 05 Jun 2023 |
|
CVE-2023-27992
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware... |
NAS326 firmware, NAS540 firmware, NAS542 firmware | Confirmed | In CISA | 23 Jun 2023 |
|
CVE-2017-18368
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the... |
P660HN-T1A v1 TCLinux Fw | Confirmed | In CISA | 07 Aug 2023 |
|
CVE-2017-6884
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in... |
EMG2926 | Confirmed | In CISA | 18 Sep 2023 |
|
CVE-2024-11667
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware | Confirmed | In CISA | 03 Dec 2024 |
|
CVE-2024-40890
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A... |
VMG4325-B10A firmware | Confirmed | In CISA | 11 Feb 2025 |
|
CVE-2024-40891
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel... |
VMG4325-B10A firmware | Confirmed | In CISA | 11 Feb 2025 |
|
CVE-2023-28770
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to... |
DX5401-B0 firmware | High | Not in CISA | 27 Apr 2023 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 10
- CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 2
- CWE-203 — Observable Discrepancy 1
- CWE-287 — Improper Authentication 1
- CWE-522 — Insufficiently Protected Credentials 1
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology