Vendor
Zyxel vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in Zyxel: 0 in the last 7 days and 5 in the last 90 days, 13 of them critical and 12 exploited in the wild. The most recent, CVE-2026-13206, was published on 10 August 2026. 4 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 13
- Exploited in the wild
- 12
About Zyxel
Zyxel Networks is a global provider of networking solutions for home and business users.
Zyxel technologies
Latest Zyxel vulnerabilities
- CVE-2026-13206: Zyxel WAH7601 OS command injectioncriticalCVSS 9.8EPSS 1.8%
- CVE-2026-14818: Zyxel ZLD firewall path traversal in configuration executionhighCVSS 7.2EPSS 0.6%
- CVE-2026-8508: Zyxel WAX650S improper authentication in social_login.cgimediumCVSS 6.5EPSS 0.3%
- CVE-2026-6837: Zyxel WAX650S command injection in export-cgihighCVSS 7.2EPSS 1.5%
- CVE-2026-6952: Zyxel multiple devices command injection in syslog LogServer fieldhighCVSS 7.2
- CVE-2026-7273: Zyxel GS1900 Series stack-based buffer overflow in CGI programcriticalexploited in the wildCVSS 8.8EPSS 1.3%
- CVE-2026-3871: Zyxel multiple CPE devices buffer overflow in UPnP DeletePortMappingmediumCVSS 6.5
- CVE-2026-3870: Zyxel VMG4005-B50B buffer overflow in UPnP AddPortMappingmediumCVSS 6.5
- CVE-2026-4795: Zyxel GS1200v3 series missing authorization in log filesmediumCVSS 6.5EPSS 0.0%
- CVE-2026-7287: Zyxel NWA1100-N buffer overflow in webs binaryhighCVSS 7.5EPSS 0.3%
- CVE-2026-7257: Zyxel WRE6505 v2 Insecure Storage in Configuration FilemediumCVSS 4.4EPSS 0.0%
- CVE-2026-7256: Zyxel WRE6505 v2 command injection in CGI programhighCVSS 8.8EPSS 0.8%
- CVE-2026-7255: Zyxel WRE6505 v2 improper authentication restriction in web interfacemediumCVSS 6.5
- CVE-2026-1460: Zyxel multiple CPE and ONT devices command injection in DHCP DomainNamehighCVSS 7.2EPSS 1.2%
- CVE-2026-0711: Zyxel Multiple Products command injection in EasyMesh APIsmediumCVSS 6.8EPSS 0.9%
- CVE-2026-6058: Zyxel WRE6505 v2 improper encoding DoS in CGI programmediumCVSS 4.5EPSS 0.2%
- CVE-2024-40890: Zyxel DSL CPE OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
Most severe Zyxel vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-30525: Zyxel Multiple Firewalls OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-9054: Zyxel Multiple NAS Devices OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-7273: Zyxel GS1900 Series stack-based buffer overflow in CGI programcriticalexploited in the wildCVSS 8.8EPSS 1.3%
- CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/zyxel.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Zyxel vulnerabilities", https://junglewise.ai/threats/vendors/zyxel, 26 September 2026.