{"schema_version":1,"title":"Zyxel vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in Zyxel: 0 in the last 7 days and 5 in the last 90 days, 13 of them critical and 12 exploited in the wild. The most recent, CVE-2026-13206, was published on 10 August 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/zyxel","json_url":"https://junglewise.ai/threats/vendors/zyxel.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/zyxel","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":27,"critical":13,"exploited":12,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":16},"latest":[{"cve":"CVE-2026-13206","cvss":9.8,"epss":0.0177,"slug":"cve-2026-13206-zyxel-wah7601-os-command-injection","title":"Zyxel WAH7601 OS command injection","severity":"critical","exploited":false,"published_at":"2026-08-10T13:17:56.02+00:00","url":"https://junglewise.ai/threats/cve-2026-13206-zyxel-wah7601-os-command-injection"},{"cve":"CVE-2026-14818","cvss":7.2,"epss":0.0057,"slug":"cve-2026-14818-zyxel-zld-firewall-path-traversal-in-configuration-execution","title":"Zyxel ZLD firewall path traversal in configuration execution","severity":"high","exploited":false,"published_at":"2026-08-04T04:16:30.93+00:00","url":"https://junglewise.ai/threats/cve-2026-14818-zyxel-zld-firewall-path-traversal-in-configuration-execution"},{"cve":"CVE-2026-8508","cvss":6.5,"epss":0.0032,"slug":"cve-2026-8508-zyxel-wax650s-improper-authentication-in-social-login-cgi","title":"Zyxel WAX650S improper authentication in social_login.cgi","severity":"medium","exploited":false,"published_at":"2026-08-04T03:16:26.023+00:00","url":"https://junglewise.ai/threats/cve-2026-8508-zyxel-wax650s-improper-authentication-in-social-login-cgi"},{"cve":"CVE-2026-6837","cvss":7.2,"epss":0.0152,"slug":"cve-2026-6837-zyxel-wax650s-command-injection-in-export-cgi","title":"Zyxel WAX650S command injection in export-cgi","severity":"high","exploited":false,"published_at":"2026-08-04T03:16:25.89+00:00","url":"https://junglewise.ai/threats/cve-2026-6837-zyxel-wax650s-command-injection-in-export-cgi"},{"cve":"CVE-2026-6952","cvss":7.2,"slug":"cve-2026-6952-zyxel-multiple-devices-command-injection-in-syslog-logserver-field","title":"Zyxel multiple devices command injection in syslog LogServer field","severity":"high","exploited":false,"published_at":"2026-07-21T03:16:42.61+00:00","url":"https://junglewise.ai/threats/cve-2026-6952-zyxel-multiple-devices-command-injection-in-syslog-logserver-field"},{"cve":"CVE-2026-7273","cvss":8.8,"epss":0.0129,"slug":"cve-2026-7273-zyxel-gs1900-series-stack-based-buffer-overflow-in-cgi-program","title":"Zyxel GS1900 Series stack-based buffer overflow in CGI program","severity":"critical","exploited":true,"published_at":"2026-06-16T03:16:13.557+00:00","url":"https://junglewise.ai/threats/cve-2026-7273-zyxel-gs1900-series-stack-based-buffer-overflow-in-cgi-program"},{"cve":"CVE-2026-3871","cvss":6.5,"slug":"cve-2026-3871-zyxel-multiple-cpe-devices-buffer-overflow-in-upnp","title":"Zyxel multiple CPE devices buffer overflow in UPnP DeletePortMapping","severity":"medium","exploited":false,"published_at":"2026-06-02T03:16:17.023+00:00","url":"https://junglewise.ai/threats/cve-2026-3871-zyxel-multiple-cpe-devices-buffer-overflow-in-upnp"},{"cve":"CVE-2026-3870","cvss":6.5,"slug":"cve-2026-3870-zyxel-vmg4005-b50b-buffer-overflow-in-upnp-addportmapping","title":"Zyxel VMG4005-B50B buffer overflow in UPnP AddPortMapping","severity":"medium","exploited":false,"published_at":"2026-06-02T03:16:16.89+00:00","url":"https://junglewise.ai/threats/cve-2026-3870-zyxel-vmg4005-b50b-buffer-overflow-in-upnp-addportmapping"},{"cve":"CVE-2026-4795","cvss":6.5,"epss":0.0004,"slug":"cve-2026-4795-zyxel-gs1200v3-series-missing-authorization-in-log-files","title":"Zyxel GS1200v3 series missing authorization in log files","severity":"medium","exploited":false,"published_at":"2026-05-26T02:16:40.36+00:00","url":"https://junglewise.ai/threats/cve-2026-4795-zyxel-gs1200v3-series-missing-authorization-in-log-files"},{"cve":"CVE-2026-7287","cvss":7.5,"epss":0.0026,"slug":"cve-2026-7287-zyxel-nwa1100-n-buffer-overflow-in-webs-binary","title":"Zyxel NWA1100-N buffer overflow in webs binary","severity":"high","exploited":false,"published_at":"2026-05-12T04:16:29.637+00:00","url":"https://junglewise.ai/threats/cve-2026-7287-zyxel-nwa1100-n-buffer-overflow-in-webs-binary"},{"cve":"CVE-2026-7257","cvss":4.4,"epss":0.0001,"slug":"cve-2026-7257-zyxel-wre6505-v2-insecure-storage-in-configuration-file","title":"Zyxel WRE6505 v2 Insecure Storage in Configuration File","severity":"medium","exploited":false,"published_at":"2026-05-12T04:16:29.497+00:00","url":"https://junglewise.ai/threats/cve-2026-7257-zyxel-wre6505-v2-insecure-storage-in-configuration-file"},{"cve":"CVE-2026-7256","cvss":8.8,"epss":0.0083,"slug":"cve-2026-7256-zyxel-wre6505-v2-command-injection-in-cgi-program","title":"Zyxel WRE6505 v2 command injection in CGI program","severity":"high","exploited":false,"published_at":"2026-05-12T04:16:29.36+00:00","url":"https://junglewise.ai/threats/cve-2026-7256-zyxel-wre6505-v2-command-injection-in-cgi-program"},{"cve":"CVE-2026-7255","cvss":6.5,"slug":"cve-2026-7255-zyxel-wre6505-v2-improper-authentication-restriction-in-web","title":"Zyxel WRE6505 v2 improper authentication restriction in web interface","severity":"medium","exploited":false,"published_at":"2026-05-12T04:16:29.143+00:00","url":"https://junglewise.ai/threats/cve-2026-7255-zyxel-wre6505-v2-improper-authentication-restriction-in-web"},{"cve":"CVE-2026-1460","cvss":7.2,"epss":0.0116,"slug":"cve-2026-1460-zyxel-multiple-cpe-and-ont-devices-command-injection-in-dhcp","title":"Zyxel multiple CPE and ONT devices command injection in DHCP DomainName","severity":"high","exploited":false,"published_at":"2026-04-28T03:16:02.313+00:00","url":"https://junglewise.ai/threats/cve-2026-1460-zyxel-multiple-cpe-and-ont-devices-command-injection-in-dhcp"},{"cve":"CVE-2026-0711","cvss":6.8,"epss":0.0091,"slug":"cve-2026-0711-zyxel-multiple-products-command-injection-in-easymesh-apis","title":"Zyxel Multiple Products command injection in EasyMesh APIs","severity":"medium","exploited":false,"published_at":"2026-04-28T03:16:02.167+00:00","url":"https://junglewise.ai/threats/cve-2026-0711-zyxel-multiple-products-command-injection-in-easymesh-apis"},{"cve":"CVE-2026-6058","cvss":4.5,"epss":0.0021,"slug":"cve-2026-6058-zyxel-wre6505-v2-improper-encoding-dos-in-cgi-program","title":"Zyxel WRE6505 v2 improper encoding DoS in CGI program","severity":"medium","exploited":false,"published_at":"2026-04-21T02:16:08.5+00:00","url":"https://junglewise.ai/threats/cve-2026-6058-zyxel-wre6505-v2-improper-encoding-dos-in-cgi-program"},{"cve":"CVE-2024-40890","cvss":8.8,"slug":"cve-2024-40890-zyxel-dsl-cpe-os-command-injection-vulnerability","title":"Zyxel DSL CPE OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-40890-zyxel-dsl-cpe-os-command-injection-vulnerability"},{"cve":"CVE-2024-40891","cvss":8.8,"slug":"cve-2024-40891-zyxel-dsl-cpe-os-command-injection-vulnerability","title":"Zyxel DSL CPE OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-40891-zyxel-dsl-cpe-os-command-injection-vulnerability"},{"cve":"CVE-2024-11667","cvss":9.8,"slug":"cve-2024-11667-zyxel-multiple-firewalls-path-traversal-vulnerability","title":"Zyxel Multiple Firewalls Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2024-12-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-11667-zyxel-multiple-firewalls-path-traversal-vulnerability"},{"cve":"CVE-2017-6884","cvss":8.8,"slug":"cve-2017-6884-zyxel-emg2926-routers-command-injection-vulnerability","title":"Zyxel EMG2926 Routers Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-09-18T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-6884-zyxel-emg2926-routers-command-injection-vulnerability"},{"cve":"CVE-2017-18368","cvss":9.8,"slug":"cve-2017-18368-zyxel-p660hn-t1a-routers-command-injection-vulnerability","title":"Zyxel P660HN-T1A Routers Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-18368-zyxel-p660hn-t1a-routers-command-injection-vulnerability"},{"cve":"CVE-2023-27992","cvss":9.8,"slug":"cve-2023-27992-zyxel-multiple-nas-devices-command-injection-vulnerability","title":"Zyxel Multiple NAS Devices Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-23T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27992-zyxel-multiple-nas-devices-command-injection-vulnerability"},{"cve":"CVE-2023-33009","cvss":9.8,"slug":"cve-2023-33009-zyxel-multiple-firewalls-buffer-overflow-vulnerability","title":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-33009-zyxel-multiple-firewalls-buffer-overflow-vulnerability"},{"cve":"CVE-2023-33010","cvss":9.8,"slug":"cve-2023-33010-zyxel-multiple-firewalls-buffer-overflow-vulnerability","title":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-33010-zyxel-multiple-firewalls-buffer-overflow-vulnerability"},{"cve":"CVE-2023-28771","cvss":9.8,"slug":"cve-2023-28771-zyxel-multiple-firewalls-os-command-injection-vulnerability","title":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-05-31T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-28771-zyxel-multiple-firewalls-os-command-injection-vulnerability"}],"vendor":{"hub":true,"name":"Zyxel","slug":"zyxel","homepage":"https://www.zyxel.com/","description":"Zyxel Networks is a global provider of networking solutions for home and business users.","url":"https://junglewise.ai/threats/vendors/zyxel"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2024-11667","cvss":9.8,"slug":"cve-2024-11667-zyxel-multiple-firewalls-path-traversal-vulnerability","title":"Zyxel Multiple Firewalls Path Traversal Vulnerability","severity":"critical","exploited":true,"published_at":"2024-12-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-11667-zyxel-multiple-firewalls-path-traversal-vulnerability"},{"cve":"CVE-2017-18368","cvss":9.8,"slug":"cve-2017-18368-zyxel-p660hn-t1a-routers-command-injection-vulnerability","title":"Zyxel P660HN-T1A Routers Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-18368-zyxel-p660hn-t1a-routers-command-injection-vulnerability"},{"cve":"CVE-2023-27992","cvss":9.8,"slug":"cve-2023-27992-zyxel-multiple-nas-devices-command-injection-vulnerability","title":"Zyxel Multiple NAS Devices Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-23T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27992-zyxel-multiple-nas-devices-command-injection-vulnerability"},{"cve":"CVE-2023-33010","cvss":9.8,"slug":"cve-2023-33010-zyxel-multiple-firewalls-buffer-overflow-vulnerability","title":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-33010-zyxel-multiple-firewalls-buffer-overflow-vulnerability"},{"cve":"CVE-2023-33009","cvss":9.8,"slug":"cve-2023-33009-zyxel-multiple-firewalls-buffer-overflow-vulnerability","title":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-33009-zyxel-multiple-firewalls-buffer-overflow-vulnerability"},{"cve":"CVE-2023-28771","cvss":9.8,"slug":"cve-2023-28771-zyxel-multiple-firewalls-os-command-injection-vulnerability","title":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-05-31T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-28771-zyxel-multiple-firewalls-os-command-injection-vulnerability"},{"cve":"CVE-2022-30525","cvss":9.8,"slug":"cve-2022-30525-zyxel-multiple-firewalls-os-command-injection-vulnerability","title":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-30525-zyxel-multiple-firewalls-os-command-injection-vulnerability"},{"cve":"CVE-2020-9054","cvss":9.8,"slug":"cve-2020-9054-zyxel-multiple-nas-devices-os-command-injection-vulnerability","title":"Zyxel Multiple NAS Devices OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-9054-zyxel-multiple-nas-devices-os-command-injection-vulnerability"},{"cve":"CVE-2026-7273","cvss":8.8,"epss":0.0129,"slug":"cve-2026-7273-zyxel-gs1900-series-stack-based-buffer-overflow-in-cgi-program","title":"Zyxel GS1900 Series stack-based buffer overflow in CGI program","severity":"critical","exploited":true,"published_at":"2026-06-16T03:16:13.557+00:00","url":"https://junglewise.ai/threats/cve-2026-7273-zyxel-gs1900-series-stack-based-buffer-overflow-in-cgi-program"},{"cve":"CVE-2024-40891","cvss":8.8,"slug":"cve-2024-40891-zyxel-dsl-cpe-os-command-injection-vulnerability","title":"Zyxel DSL CPE OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-40891-zyxel-dsl-cpe-os-command-injection-vulnerability"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Zyxel Firewalls","slug":"firewalls","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/firewalls"},{"name":"Zyxel Multiple Firewalls","slug":"multiple-firewalls","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/multiple-firewalls"},{"name":"Zyxel Wre6505","slug":"wre6505","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/wre6505"},{"name":"Zyxel Wre6505 Firmware","slug":"wre6505-firmware","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/wre6505-firmware"}]}