Skip to content
COOEY

FAIL › dossier

Multiple Firewalls

PRODUCT

· dossier confidence 60%

Zyxel firewalls have a documented history of critical security vulnerabilities, including multiple remote code execution flaws, raising concerns about their overall security posture and potential risks for DIB/CMMC compliance.

PROFILE
CategoryCybersecurityWhat they doPalo Alto Networks provides cybersecurity solutions, including Prisma Access and Strata Cloud Manager.SizeApproximately 11,000 employeesOwnershipPublic (PANW) Websitehttps://stockanalysis.com/stocks/panw/company/ ↗
SECURITY POSTURE

Zyxel firewalls have a history of critical and high-severity vulnerabilities, including remote code execution (RCE) and command injection flaws, indicating a potentially weak security posture.

Notable failures
  • CVE-2024-11667: Path traversal flaw
  • CVE-2023-33010: Buffer overflow vulnerability (RCE)
  • CVE-2023-33009: Buffer overflow vulnerability (RCE)
  • CVE-2023-28771: Improper error message handling (RCE)
  • CVE-2022-30525: Command injection vulnerability (RCE)
Patterns: Recurring RCE vulnerabilities; Vulnerabilities in web management interfaces; Improper error handling leading to command execution
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-05-16 CVE-2022-30525 high Zyxel firewalls suffered a command injection flaw allowing attackers to execute arbitrary OS commands and modify files.
2024-12-03 CVE-2024-11667 critical Zyxel firewalls had a path traversal flaw in their web management interface that allowed attackers to upload or download files via crafted URLs.
2023-06-05 CVE-2023-33010 high Zyxel Multiple Firewalls Buffer Overflow Vulnerability
2023-06-05 CVE-2023-33009 high Zyxel Multiple Firewalls Buffer Overflow Vulnerability
2023-05-31 CVE-2023-28771 high Zyxel firewalls allow remote command execution via crafted packets.
Open questions: What is Zyxel's current security development lifecycle? · What remediation steps have been taken to address the identified vulnerabilities? · What is the extent of the impact from these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:22:00.472402+00:00