Zyxel Corporation manufactures a broad portfolio of network appliances and security devices, particularly its widely deployed USG Flex series of unified security gateways that serve small to mid-sized organizations and enterprise branch offices. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the internet-facing role and embedded-systems heritage of its firewall and gateway products. The exposure recurs across the USG Flex product line through weakness classes including OS command injection, classic buffer overflows, hard-coded credentials, and cross-site scripting—patterns typical of network appliances where parsing, firmware authenticity, and administrative interfaces become high-value targets. Defenders should prioritize inventory and patching of internet-exposed Zyxel gateways and review whether end-of-life devices remain in service; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zyxel Corporation over time
Of all the CVEs published by Zyxel Corporation as a CNA, 96.3% affect products that Zyxel Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Zyxel Corporation, 47.6% are self-published by Zyxel Corporation as a CNA.
Signals from CVEs in this vendor scope (330 CVEs).
330 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30525CRITICAL A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch | May 12, 2022 | 9.8 | 99 | YES | YES |
CVE-2023-28771CRITICAL Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4. | Apr 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2020-9054CRITICAL Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthen | Mar 4, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-29583CRITICAL Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the fi | Dec 22, 2020 | 9.8 | 97 | YES | YES |
CVE-2017-18368CRITICAL The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding functi | May 2, 2019 | 9.8 | 97 | YES | YES |
CVE-2023-27992CRITICAL The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS5 | Jun 19, 2023 | 9.8 | 94 | YES | NO |
CVE-2017-6884HIGH A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically | Apr 6, 2017 | 8.8 | 89 | YES | YES |
CVE-2024-29972CRITICAL ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmwa | Jun 4, 2024 | 9.8 | 86 | NO | YES |
CVE-2024-29973CRITICAL ** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versi | Jun 4, 2024 | 9.8 | 85 | NO | YES |
CVE-2022-0342CRITICAL An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP s | Mar 28, 2022 | 9.8 | 83 | NO | YES |
Signals from CVEs in this vendor scope (330 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zyxel Corporation.
Media articles that mention a CVE ID that affects a product developed by Zyxel Corporation — matched by CVE ID, not by vendor name.