Zyxel Vulnerabilities and Affected Products
Vulnerabilities associated with VMG3625-T50B firmware.
Products
Clear product- USG FLEX series firmware51 vulnerabilities
- ATP series firmware49 vulnerabilities
- VPN series firmware37 vulnerabilities
- USG FLEX 50(W) series firmware28 vulnerabilities
- USG20(W)-VPN series firmware28 vulnerabilities
- NAS326 firmware15 vulnerabilities
- NAS542 firmware14 vulnerabilities
- USG FLEX 50(W) firmware11 vulnerabilities
- nas326_firmware9 vulnerabilities
- nas542_firmware9 vulnerabilities
- usg_flex_50w_firmware9 vulnerabilities
- USG/ZyWALL series firmware8 vulnerabilities
- USG20(W)-VPN firmware8 vulnerabilities
- VMG8825-T50K firmware8 vulnerabilities
- VMG3625-T50B firmware7 vulnerabilities
- WAC500 firmware7 vulnerabilities
- atp800_firmware6 vulnerabilities
- usg_flex_700h_firmware6 vulnerabilities
- Multiple Firewalls5 vulnerabilities
- NBG-418N v2 firmware5 vulnerabilities
- NR7101 firmware5 vulnerabilities
- NWA50AX firmware5 vulnerabilities
- usg_flex_firmware5 vulnerabilities
- WBE660S firmware5 vulnerabilities
- ZyWALL/USG series firmware5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-1459HIGH | Generated title:Zyxel VMG3625-T50B Firmware Post-Authentication OS Command InjectionA post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device. CWE-78Feb 24, 2026 | CVSS7.2v3.1 | EPSS0.902% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11848MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11847MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11846MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 Firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11845MEDIUM | Generated title:Zyxel VMG3625-T50B and WX3100-T0 firmware Null Pointer Dereference Denial of ServiceA null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. CWE-476Feb 24, 2026 | CVSS4.9v3.1 | EPSS0.782% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9197MEDIUM | A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled. CWE-120Dec 3, 2024 | CVSS4.9v3.1 | EPSS0.489% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-35036MEDIUM | A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file. CWE-312Mar 1, 2022 | CVSS6.5v3.1 | EPSS0.49% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |