Zyxel vendor intelligence

Zyxel Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Zyxel products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Zyxel KEVs Full KEV feed
Total KEVs
16
Known exploited vulnerabilities affecting Zyxel products
In CISA KEV
12
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
2
Zyxel KEVs with sensor-observed exploitation activity

The catalog gap matters for Zyxel exposure

Four of the sixteen exploited Zyxel CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-quarter of this vendor portfolio.

75%
Covered by CISA
25%
Beyond CISA
13
Product families

Attested Zyxel CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2024-29972

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before...

NAS326 firmware, NAS542 firmware Confirmed Beyond CISA 15 Jul 2026
CVE-2021-3297

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

NBG2105 High Beyond CISA 16 Sep 2025
CVE-2024-29973

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before...

NAS326 firmware, NAS542 firmware High Beyond CISA 26 Jun 2025
CVE-2020-29583

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account...

USG devices Confirmed In CISA 03 Nov 2021
CVE-2020-9054

ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi

NAS326, NAS520, NAS540, NAS542, NSA210, NSA220, NSA220+, NSA221, NSA310, NSA320, NSA320S, NSA325, NSA325v2 Confirmed In CISA 25 Mar 2022
CVE-2022-30525

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware...

USG FLEX 100(W) firmware, USG FLEX 200 firmware, USG FLEX 500 firmware, USG FLEX 700 firmware, ATP series firmware, VPN series firmware, USG FLEX 50(W) firmware, USG 20(W)-VPN firmware Confirmed In CISA 16 May 2022
CVE-2023-28771

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG...

ZyWALL/USG series firmware, VPN series firmware, USG FLEX series firmware, ATP series firmware Confirmed In CISA 31 May 2023
CVE-2023-33010

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series...

ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware Confirmed In CISA 05 Jun 2023
CVE-2023-33009

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series...

ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware Confirmed In CISA 05 Jun 2023
CVE-2023-27992

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware...

NAS326 firmware, NAS540 firmware, NAS542 firmware Confirmed In CISA 23 Jun 2023
CVE-2017-18368

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the...

P660HN-T1A v1 TCLinux Fw Confirmed In CISA 07 Aug 2023
CVE-2017-6884

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in...

EMG2926 Confirmed In CISA 18 Sep 2023
CVE-2024-11667

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series...

ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware Confirmed In CISA 03 Dec 2024
CVE-2024-40890

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A...

VMG4325-B10A firmware Confirmed In CISA 11 Feb 2025
CVE-2024-40891

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel...

VMG4325-B10A firmware Confirmed In CISA 11 Feb 2025
CVE-2023-28770

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to...

DX5401-B0 firmware High Beyond CISA 27 Apr 2023

Showing 16 of 16 Zyxel known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, buffer copy without checking size, and observable discrepancy account for thirteen mapped occurrences across this Zyxel KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.