Zyxel vendor intelligence
Zyxel Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Zyxel products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 16
- Known exploited vulnerabilities affecting Zyxel products
- In CISA KEV
- 12
- Records also listed in the official catalog
- Beyond CISA KEV
- 4
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 2
- Zyxel KEVs with sensor-observed exploitation activity
The catalog gap matters for Zyxel exposure
Four of the sixteen exploited Zyxel CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss one-quarter of this vendor portfolio.
- 75%
- Covered by CISA
- 25%
- Beyond CISA
- 13
- Product families
Attested Zyxel CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-29972
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before... |
NAS326 firmware, NAS542 firmware | Confirmed | Beyond CISA | 15 Jul 2026 |
|
CVE-2021-3297
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. |
NBG2105 | High | Beyond CISA | 16 Sep 2025 |
|
CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before... |
NAS326 firmware, NAS542 firmware | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2020-29583
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account... |
USG devices | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-9054
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi |
NAS326, NAS520, NAS540, NAS542, NSA210, NSA220, NSA220+, NSA221, NSA310, NSA320, NSA320S, NSA325, NSA325v2 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware... |
USG FLEX 100(W) firmware, USG FLEX 200 firmware, USG FLEX 500 firmware, USG FLEX 700 firmware, ATP series firmware, VPN series firmware, USG FLEX 50(W) firmware, USG 20(W)-VPN firmware | Confirmed | In CISA | 16 May 2022 |
|
CVE-2023-28771
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG... |
ZyWALL/USG series firmware, VPN series firmware, USG FLEX series firmware, ATP series firmware | Confirmed | In CISA | 31 May 2023 |
|
CVE-2023-33010
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | Confirmed | In CISA | 05 Jun 2023 |
|
CVE-2023-33009
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | Confirmed | In CISA | 05 Jun 2023 |
|
CVE-2023-27992
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware... |
NAS326 firmware, NAS540 firmware, NAS542 firmware | Confirmed | In CISA | 23 Jun 2023 |
|
CVE-2017-18368
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the... |
P660HN-T1A v1 TCLinux Fw | Confirmed | In CISA | 07 Aug 2023 |
|
CVE-2017-6884
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in... |
EMG2926 | Confirmed | In CISA | 18 Sep 2023 |
|
CVE-2024-11667
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series... |
ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware | Confirmed | In CISA | 03 Dec 2024 |
|
CVE-2024-40890
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A... |
VMG4325-B10A firmware | Confirmed | In CISA | 11 Feb 2025 |
|
CVE-2024-40891
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel... |
VMG4325-B10A firmware | Confirmed | In CISA | 11 Feb 2025 |
|
CVE-2023-28770
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to... |
DX5401-B0 firmware | High | Beyond CISA | 27 Apr 2023 |
No Zyxel CVEs match this search or filter.
Showing 16 of 16 Zyxel known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, buffer copy without checking size, and observable discrepancy account for thirteen mapped occurrences across this Zyxel KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-203
Observable Discrepancy
CWE-287
Improper Authentication
CWE-522
Insufficiently Protected Credentials
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.