Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zyxel Corporation

First CVE: Aug 14, 2001Active for: 25 yearsTotal CVEs: 330
66.1
VTI Score
TOP TARGET

Zyxel Corporation manufactures a broad portfolio of network appliances and security devices, particularly its widely deployed USG Flex series of unified security gateways that serve small to mid-sized organizations and enterprise branch offices. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the internet-facing role and embedded-systems heritage of its firewall and gateway products. The exposure recurs across the USG Flex product line through weakness classes including OS command injection, classic buffer overflows, hard-coded credentials, and cross-site scripting—patterns typical of network appliances where parsing, firmware authenticity, and administrative interfaces become high-value targets. Defenders should prioritize inventory and patching of internet-exposed Zyxel gateways and review whether end-of-life devices remain in service; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
330
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
3.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zyxel Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2001
24 years ago
Most Recent CVE
May 12, 2026
73 days ago

Self-Reporting Analysis

Of all the CVEs published by Zyxel Corporation as a CNA, 96.3% affect products that Zyxel Corporation develops as a vendor.

96.3%
Self-reported: 157 (96.3%)
Third-party: 6 (3.7%)

Of all the CVEs published that affect products developed by Zyxel Corporation, 47.6% are self-published by Zyxel Corporation as a CNA.

47.6%
52.4%
Self-published: 157 (47.6%)
Other CNAs: 173 (52.4%)

Products(884 total)

Top CVEs

Signals from CVEs in this vendor scope (330 CVEs).

330 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-30525CRITICAL
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch
May 12, 20229.899YESYES
CVE-2023-28771CRITICAL
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.
Apr 25, 20239.898YESYES
CVE-2020-9054CRITICAL
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthen
Mar 4, 20209.898YESYES
CVE-2020-29583CRITICAL
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the fi
Dec 22, 20209.897YESYES
CVE-2017-18368CRITICAL
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding functi
May 2, 20199.897YESYES
CVE-2023-27992CRITICAL
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS5
Jun 19, 20239.894YESNO
CVE-2017-6884HIGH
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically
Apr 6, 20178.889YESYES
CVE-2024-29972CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmwa
Jun 4, 20249.886NOYES
CVE-2024-29973CRITICAL
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versi
Jun 4, 20249.885NOYES
CVE-2022-0342CRITICAL
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP s
Mar 28, 20229.883NOYES
View all 330 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products330 CVEs
41%
41%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local28 (8.5%)
Network228 (69.1%)
Unknown50 (15.2%)
Physical1 (0.3%)
Adjacent Network23 (7.0%)
Attack Complexity
Low261 (79.1%)
High19 (5.8%)
Unknown50 (15.2%)
User Interaction
None253 (76.7%)
Unknown50 (15.2%)
Required27 (8.2%)
Privileges Required
Low71 (21.5%)
High42 (12.7%)
None167 (50.6%)
Unknown50 (15.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (330 CVEs).

CISA KEV
12 CVEs
3.6% of CVEs· 99th percentile
Metasploit
10 CVEs
3.0% of CVEs· 98th percentile
Nuclei
12 CVEs
3.6% of CVEs· 95th percentile
ExploitDB
22 CVEs
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zyxel Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zyxel Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zyxel Corporation's Products

View all 6 CNAs →

Top CWEs