Skip to content

Products › Brands

Brand

Zyxel: actively exploited vulnerabilities

13 vulnerabilities in Zyxel products (Firewalls (ATP, USG FLEX, ZyWALL/USG), Home gateways and routers (DSL, CPE), NAS…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: September 21, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Zyxel category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

Follow a single Zyxel product (Firewalls (ATP, USG FLEX, ZyWALL/USG), Home gateways and routers (DSL, CPE)…) rather than the whole brand.

  • Firewalls (ATP, USG FLEX, ZyWALL/USG)6 vulnerabilities, Firewalls and VPNs
  • Home gateways and routers (DSL, CPE)4 vulnerabilities, Home routers and IoT
  • NAS2 vulnerabilities, Backup and NAS
  • Switches (GS, XGS)1 vulnerability, Switches and routers

Name used by CISA: Zyxel. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Zyxel list.

  1. Rank 1

    Zyxel Switches (GS, XGS)CVE-2026-7273

    Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 8.8high

    Added Sep 21, 2026

  2. Rank 2

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2024-11667

    Zyxel Multiple Firewalls Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Dec 3, 2024

  3. Rank 3

    Zyxel Home gateways and routers (DSL, CPE)CVE-2017-18368

    Zyxel P660HN-T1A Routers Command Injection Vulnerability

    CVE from 2017, added in 2023

    CVSS severity 9.8critical

    Added Aug 7, 2023

  4. Rank 4

    Zyxel NASCVE-2023-27992

    Zyxel Multiple NAS Devices Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 23, 2023

  5. Rank 5

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2023-33009

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    CVSS severity 9.8critical

    Added Jun 5, 2023

  6. Rank 6

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2023-33010

    Zyxel Multiple Firewalls Buffer Overflow Vulnerability

    CVSS severity 9.8critical

    Added Jun 5, 2023

  7. Rank 7

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2023-28771

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    CVSS severity 9.8critical

    Added May 31, 2023

  8. Rank 8

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2022-30525

    Zyxel Multiple Firewalls OS Command Injection Vulnerability

    CVSS severity 9.8critical

    Added May 16, 2022

  9. Rank 9

    Zyxel NASCVE-2020-9054

    Zyxel Multiple NAS Devices OS Command Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  10. Rank 10

    Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)CVE-2020-29583

    Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

Show 3 more vulnerabilities
  1. Rank 11

    Zyxel Home gateways and routers (DSL, CPE)CVE-2024-40890

    Zyxel DSL CPE OS Command Injection Vulnerability

    CVSS severity 8.8high

    Added Feb 11, 2025

  2. Rank 12

    Zyxel Home gateways and routers (DSL, CPE)CVE-2024-40891

    Zyxel DSL CPE OS Command Injection Vulnerability

    CVSS severity 8.8high

    Added Feb 11, 2025

  3. Rank 13

    Zyxel Home gateways and routers (DSL, CPE)CVE-2017-6884

    Zyxel EMG2926 Routers Command Injection Vulnerability

    RansomwareCVE from 2017, added in 2023

    CVSS severity 8.8high

    Added Sep 18, 2023

Follow and verify

Get new Zyxel vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.