Zyxel Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Zyxel products.
Products
- USG FLEX series firmware51 vulnerabilities
- ATP series firmware49 vulnerabilities
- VPN series firmware37 vulnerabilities
- USG FLEX 50(W) series firmware28 vulnerabilities
- USG20(W)-VPN series firmware28 vulnerabilities
- NAS326 firmware15 vulnerabilities
- NAS542 firmware14 vulnerabilities
- USG FLEX 50(W) firmware11 vulnerabilities
- nas326_firmware9 vulnerabilities
- nas542_firmware9 vulnerabilities
- usg_flex_50w_firmware9 vulnerabilities
- USG/ZyWALL series firmware8 vulnerabilities
- USG20(W)-VPN firmware8 vulnerabilities
- VMG8825-T50K firmware8 vulnerabilities
- VMG3625-T50B firmware7 vulnerabilities
- WAC500 firmware7 vulnerabilities
- atp800_firmware6 vulnerabilities
- usg_flex_700h_firmware6 vulnerabilities
- Multiple Firewalls5 vulnerabilities
- NBG-418N v2 firmware5 vulnerabilities
- NR7101 firmware5 vulnerabilities
- NWA50AX firmware5 vulnerabilities
- usg_flex_firmware5 vulnerabilities
- WBE660S firmware5 vulnerabilities
- ZyWALL/USG series firmware5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-14818HIGH | Generated title:Zyxel ATP and USG FLEX Series Firmware Path Traversal VulnerabilityA path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an a… CWE-22Aug 4, 2026 | CVSS7.2v3.1 | EPSS0.359% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8508MEDIUM | Generated title:Zyxel WAX650S Firmware Improper Authentication in social_login.cgi Allows Captive Portal BypassAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication. CWE-287Aug 4, 2026 | CVSS6.5v3.1 | EPSS0.544% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6837HIGH | Generated title:Zyxel WAX650S firmware export-cgi post-authentication OS command injectionA post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. CWE-78Aug 4, 2026 | CVSS7.2v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6952HIGH | Generated title:Zyxel AX7501-B1 firmware post-authentication OS command injection in syslog LogServer fieldA post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. CWE-78Jul 21, 2026 | CVSS7.2v3.1 | EPSS0.95% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7273HIGH | Generated title:Zyxel GS1900 Series Firmware Stack-Based Buffer Overflow in CGI ProgramA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. CWE-121Jun 16, 2026 | CVSS8.8v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3871MEDIUM | Generated title:Zyxel VMG4005-B50B Firmware UPnP DeletePortMapping Buffer Overflow Denial of ServiceA buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device. CWE-120Jun 2, 2026 | CVSS6.5v3.1 | EPSS0.168% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3870MEDIUM | Generated title:Zyxel VMG4005-B50B Firmware UPnP AddPortMapping Buffer Overflow Denial of ServiceA buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device. CWE-120Jun 2, 2026 | CVSS6.5v3.1 | EPSS0.168% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4795MEDIUM | Generated title:Zyxel GS1200 Series Firmware Missing Authorization Information DisclosureA missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request. CWE-862May 26, 2026 | CVSS6.5v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7287HIGH | Generated title:Zyxel NWA1100-N Firmware Buffer Overflow Denial-of-Service Vulnerability** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request to a vulnerable device. CWE-120May 12, 2026 | CVSS7.5v3.1 | EPSS0.309% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7257MEDIUM | Generated title:Zyxel WRE6505 v2 Firmware Insecure Storage of Sensitive Information in Configuration File** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file. CWE-922May 12, 2026 | CVSS4.4v3.1 | EPSS0.108% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7256HIGH | Generated title:Zyxel WRE6505 v2 Firmware CGI Program OS Command Injection** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request. CWE-78May 12, 2026 | CVSS8.8v3.1 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7255MEDIUM | Generated title:Zyxel WRE6505 v2 Firmware Improper Restriction of Excessive Authentication Attempts** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication. CWE-307May 12, 2026 | CVSS6.5v3.1 | EPSS0.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1460HIGH | Generated title:Zyxel DX3301-T0 and EX3301-T0 Firmware Post-Authentication Command Injection in DHCP DomainName ParameterA post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. CWE-78Apr 28, 2026 | CVSS7.2v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0711MEDIUM | Generated title:Zyxel DX3300-T0 Firmware Post-Authentication Command Injection in EasyMesh APIsA post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device. CWE-78Apr 28, 2026 | CVSS6.8v3.1 | EPSS0.849% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6058MEDIUM | Generated title:Zyxel WRE6505 v2 Firmware Improper Encoding or Escaping Denial of Service** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while a malformed SSID is present. CWE-116Apr 21, 2026 | CVSS4.5v3.1 | EPSS0.182% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1459HIGH | Generated title:Zyxel VMG3625-T50B Firmware Post-Authentication OS Command InjectionA post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device. CWE-78Feb 24, 2026 | CVSS7.2v3.1 | EPSS0.902% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13943HIGH | Generated title:Zyxel EX3301-T0 Firmware Post-Authentication Command InjectionA post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. CWE-78Feb 24, 2026 | CVSS8.8v3.1 | EPSS1.4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13942CRITICAL | Generated title:Zyxel EX3510-B0 UPnP Command InjectionA command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests. CWE-78Feb 24, 2026 | CVSS9.8v3.1 | EPSS1.06% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11848MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11847MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11846MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11845MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.782% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11730HIGH | Generated title:Zyxel ATP/USG FLEX/USG20(W)-VPN Series Firmware Post-Authentication OS Command Injection in DDNS CLIA post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.41, USG FLEX series firmware versions from V5.35 through V5.41, USG FLEX 50(W) series firmware versions from V5.35 through V5.41, and USG20(W)-VPN series firmware versions from V5.35 through V5.41 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device by su… CWE-78Feb 5, 2026 | CVSS7.2v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8693HIGH | A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device. CWE-78Nov 18, 2025 | CVSS8.8v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6599MEDIUM | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web management interface, while other networking services remain unaffected. CWE-400Nov 18, 2025 | CVSS5.3v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |