Zyxel Corporation
First CVE: Jul 2, 2021Active for: 5 years
163
CVEs Published
More CVEs Published than 77% of tracked CNAs
27.2
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 63% of tracked CNAs
4.9%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Zyxel Corporation as a CNA, 96.3% affect products that Zyxel Corporation develops as a vendor.
96.3%
Self-reported: 157Third-party: 6
Of all the CVEs published that affect products developed by Zyxel Corporation, 47.6% are self-published by Zyxel Corporation as a CNA.
47.6%
52.4%
Self-published: 157Published by other CNAs: 173
Trends Over Time
The number and severity of CVEs published by Zyxel Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2021
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Zyxel Corporation as a CNA, regardless of affected vendor or product.
163 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30525CRITICAL A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch | May 12, 2022 | 9.8 | 99 | YES | YES |
CVE-2023-28771CRITICAL Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4. | Apr 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-27992CRITICAL The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS5 | Jun 19, 2023 | 9.8 | 94 | YES | NO |
CVE-2024-29972CRITICAL ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmwa | Jun 4, 2024 | 9.8 | 86 | NO | YES |
CVE-2024-29973CRITICAL ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versi | Jun 4, 2024 | 9.8 | 85 | NO | YES |
CVE-2022-0342CRITICAL An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP s | Mar 28, 2022 | 9.8 | 83 | NO | YES |
CVE-2023-33009CRITICAL A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Pa | May 24, 2023 | 9.8 | 82 | YES | NO |
CVE-2023-33010CRITICAL A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 P | May 24, 2023 | 9.8 | 80 | YES | NO |
CVE-2024-40891HIGH **UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4 | Feb 4, 2025 | 8.8 | 78 | YES | NO |
CVE-2021-4039CRITICAL A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device. | Mar 1, 2022 | 9.8 | 78 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA163 CVEs
39%
44%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local26 (16.0%)
Network111 (68.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network26 (16.0%)
Attack Complexity
Low159 (97.5%)
High4 (2.5%)
Unknown0 (0.0%)
User Interaction
None150 (92.0%)
Unknown0 (0.0%)
Required13 (8.0%)
Privileges Required
Low47 (28.8%)
High42 (25.8%)
None74 (45.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (163 CVEs).
CISA KEV
8 CVEs
4.9% of CVEs· 96th percentile
Metasploit
6 CVEs
3.7% of CVEs· 95th percentile
Nuclei
4 CVEs
2.5% of CVEs· 88th percentile
ExploitDB
3 CVEs
1.8% of CVEs· 88th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Zyxel Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Zyxel Corporation as a CNA — matched by CVE ID, not by organization name.