Skip to main content

Daily materialized evidence profile

Vendor zyxel

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
328
CVEs with mentions
98
Total mentions
295
CVEs with KEV
12
CVEs with PoC
2

Attack vector counts

Network
270
Adjacent network
31
Local
26
Physical
1

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2022-30525

Published May 12, 2022

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patc…

CVSS 9.8 · Critical
evidence mentions
13
Buzz score
71.8
KEV listedPublic PoC observed

CVE-2023-28771

Published Apr 25, 2023

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4…

CVSS 9.8 · Critical
evidence mentions
26
Buzz score
69.5
KEV listed

CVE-2020-9054

Published Mar 4, 2020

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthe…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
65.2
KEV listed

CVE-2017-6884

Published Apr 6, 2017

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically…

CVSS 8.8 · High
evidence mentions
6
Buzz score
64.5
KEV listed

CVE-2023-27992

Published Jun 19, 2023

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
63.6
KEV listed