Zyxel Corporation

First CVE: Jul 2, 2021Active for: 5 years
163
CVEs Published
More CVEs Published than 77% of tracked CNAs
27.2
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 63% of tracked CNAs
4.9%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Zyxel Corporation as a CNA, 96.3% affect products that Zyxel Corporation develops as a vendor.

96.3%
Self-reported: 157Third-party: 6

Of all the CVEs published that affect products developed by Zyxel Corporation, 47.6% are self-published by Zyxel Corporation as a CNA.

47.6%
52.4%
Self-published: 157Published by other CNAs: 173

Trends Over Time

The number and severity of CVEs published by Zyxel Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2021
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Zyxel Corporation as a CNA, regardless of affected vendor or product.

163 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch
May 12, 20229.899YESYES
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.
Apr 25, 20239.898YESYES
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS5
Jun 19, 20239.894YESNO
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmwa
Jun 4, 20249.886NOYES
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versi
Jun 4, 20249.885NOYES
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP s
Mar 28, 20229.883NOYES
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Pa
May 24, 20239.882YESNO
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 P
May 24, 20239.880YESNO
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4
Feb 4, 20258.878YESNO
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
Mar 1, 20229.878NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA163 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local26 (16.0%)
Network111 (68.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network26 (16.0%)
Attack Complexity
Low159 (97.5%)
High4 (2.5%)
Unknown0 (0.0%)
User Interaction
None150 (92.0%)
Unknown0 (0.0%)
Required13 (8.0%)
Privileges Required
Low47 (28.8%)
High42 (25.8%)
None74 (45.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (163 CVEs).

CISA KEV
8 CVEs
4.9% of CVEs· 96th percentile
Metasploit
6 CVEs
3.7% of CVEs· 95th percentile
Nuclei
4 CVEs
2.5% of CVEs· 88th percentile
ExploitDB
3 CVEs
1.8% of CVEs· 88th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Zyxel Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Zyxel Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs