zyxel

330 tracked vulnerabilities.

CVE-2026-7287 HIGH
Zyxel NWA1100-N Firmware - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
May 12, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-7257 MEDIUM
Zyxel WRE6505 v2 firmware V1.00(ABDV.3)C0 - Insecure Storage of Sensitive Information in Configuration File
May 12, 2026
CVSS 4.4
EPSS 0.00
CVE-2026-7256 HIGH
Zyxel WRE6505 v2 Firmware - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
May 12, 2026
CVSS 8.8
EPSS 0.01
CVE-2026-7255 MEDIUM
Zyxel WRE6505 v2 Firmware - Improper Restriction of Excessive Authentication Attempts
May 12, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-1460 HIGH
Zyxel DX3301-T0 & EX3301-T0 <= 5.50(ABVY.7.1)C0 Authenticated OS Command Injection via DHCP
Apr 28, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-0711 MEDIUM
Zyxel DX3300-T0 firmware <= 5.50(ABVY.7.1)C0 - Authenticated OS Command Injection via EasyMesh API
Apr 28, 2026
CVSS 6.8
EPSS 0.00
CVE-2026-6058 MEDIUM
Zyxel WRE6505 v2 firmware V1.00(ABDV.3)C0 - Denial of Service via Malformed SSID on AP Select Page
Apr 21, 2026
CVSS 4.5
EPSS 0.00
CVE-2026-1459 HIGH
Zyxel VMG3625-T50B <5.50(ABPM.9.7)C0 - Command Injection
Feb 24, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-13943 HIGH
Zyxel EX3301-T0 <5.50(ABVY.7)C0 - Command Injection
Feb 24, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-13942 CRITICAL
Zyxel EX3510-B0 <5.17(ABUP.15.1)C0 - Command Injection
Feb 24, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-11848 MEDIUM
Zyxel VMG3625-T50B and WX3100-T0 Firmware - Authenticated Denial of Service via Wake-on-LAN CGI Program
Feb 24, 2026
CVSS 4.9
EPSS 0.00
CVE-2025-11847 MEDIUM
Zyxel LTE3301-PLUS Firmware < 1.00(ABQU.9)C0 - Authenticated Denial of Service via IP Settings CGI Program
Feb 24, 2026
CVSS 4.9
EPSS 0.00
CVE-2025-11846 MEDIUM
Zyxel LTE3301-PLUS Firmware < 1.00(ABQU.9)C0 - Authenticated Denial of Service via Account Settings CGI Program
Feb 24, 2026
CVSS 4.9
EPSS 0.00
CVE-2025-11845 MEDIUM
Zyxel LTE3301-PLUS Firmware < 1.00(abqu.9)c0 - Authenticated Denial of Service via Certificate Downloader CGI Program
Feb 24, 2026
CVSS 4.9
EPSS 0.00
CVE-2025-11730 HIGH
Zyxel ATP-USG FLEX-50(W)-USG20(W)-VPN <5.41 - Command Injection
Feb 05, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-8693 HIGH
Zyxel DX3300-T0 Firmware < 5.50(ABVY.6.3)C0 - Authenticated OS Command Injection via priv Parameter
Nov 18, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-6599 MEDIUM
Zyxel DX3301-T0 <5.50(ABVY.6.3)C0 - DoS
Nov 18, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-9133 HIGH
Zyxel ATP-USG FLEX-20(W)-VPN - Info Disclosure
Oct 21, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-8078 HIGH
Zyxel ZLD 4.32-5.40 - Authenticated OS Command Injection via CLI Argument
Oct 21, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-7673 CRITICAL
Zyxel VMG8825-T50K <V5.50(ABOM.5)C0 - Buffer Overflow
Jul 16, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-6265 HIGH
Zyxel NWA50AX PRO <7.10(ACGE.2 - Path Traversal
Jul 15, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-3577 MEDIUM
Zyxel AMG1302-T10B Firmware 2.00(AAJC.16)C0 - Authenticated Path Traversal
Apr 22, 2025
CVSS 4.9
EPSS 0.03
CVE-2025-1732 MEDIUM
Zyxel USG FLEX H uOS <= V1.31 - Authenticated Privilege Escalation via Crafted Configuration File Upload
Apr 22, 2025
CVSS 6.7
EPSS 0.00
CVE-2025-1731 HIGH
Zyxel uOS 1.20-1.31 - Authenticated Privilege Escalation via PostgreSQL Command Injection
Apr 22, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-0890 CRITICAL
Zyxel Legacy DSL CPE Firmware - Insecure Default Telnet Credentials
Feb 04, 2025
CVSS 9.8
EPSS 0.22