← Back

Zyxel

zyxel

329 CVEs • 885 products

Products (885)

Click to collapse
Toggle
Zld
zld
Zynos
zynos

CVEs (329)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zyxel
16Atp100 Firmware
Atp100w FirmwareAtp200 Firmware+13 more
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00...Show more
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.Show less
1Zyxel
32Ax7501 B0 Firmware
Dx5401 B0 FirmwareEmg3525 T50b Firmware+29 more
Jun 17, 2026
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of s...Show more
A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service.Show less
1Zyxel
32Ax7501 B0 Firmware
Dx5401 B0 FirmwareEmg3525 T50b Firmware+29 more
Jun 17, 2026
Apr 11, 2022
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN inte...Show more
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.Show less
1Zyxel
1Zyxel Ap Configurator
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a loca...Show more
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.Show less
1Zyxel
23Atp100 Firmware
Atp100w FirmwareAtp200 Firmware+20 more
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.2...Show more
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.Show less
1Zyxel
1Zywall 2 Plus Internet Security Appliance Firmware
Jun 17, 2026
Mar 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to exec...Show more
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.Show less
1Zyxel
1Nwa1100 Nh Firmware
Jun 17, 2026
Mar 1, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
1Zyxel
31Ax7501 B0 Firmware
Dx3301 T0 FirmwareDx5401 B0 Firmware+28 more
Jun 17, 2026
Mar 1, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
1Zyxel
2Nbg6816 Firmware
Nbg6817 Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website wi...Show more
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.Show less
1Zyxel
2Nbg6816 Firmware
Nbg6817 Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.
1Zyxel
1Nbg6604 Firmware
Jun 17, 2026
Dec 29, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
1Zyxel
1Nbg6604 Firmware
Jun 17, 2026
Dec 29, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
1Zyxel
12Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+9 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
1Zyxel
14Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+11 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vu...Show more
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.Show less
1Zyxel
6Nbg6818 Firmware
Nbg7815 FirmwareWsq20 Firmware+3 more
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local at...Show more
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.Show less
1Zyxel
1Zywall Vpn2s Firmware
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
1Zyxel
1Zywall Vpn2s Firmware
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
1Zyxel
12Gs1900 10hp Firmware
Gs1900 16 FirmwareGs1900 24 Firmware+9 more
Jun 17, 2026
Jul 26, 2021
N/A· v4
4.3 MEDIUM· v3
2.3 LOW· v2
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS)...Show more
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.Show less
1Zyxel
37Usg1000 Firmware
Usg100 FirmwareUsg1100 Firmware+34 more
Jun 17, 2026
Jul 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which co...Show more
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.Show less
1Zyxel
3Lte4506 M606 Firmware
Lte7460 M608 FirmwareWah7706 Firmware
Jun 17, 2026
Mar 16, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provi...Show more
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.Show less