Skip to content
COOEY

FAIL › dossier

Zyxel

VENDOR

· dossier confidence 40%

Zyxel is a Taiwanese network security hardware vendor with a documented history of releasing products containing critical and high-severity vulnerabilities, including command injection and buffer overflow flaws in routers, firewalls, and NAS devices. The company's security posture is characterized by a high frequency of CVEs that require patching, indicating a need for rigorous internal security testing and vulnerability management.

PROFILE
Categorynetwork security hardwareWhat they doZyxel Group Corp designs and manufactures network security hardware, including routers, firewalls, and network-attached storage devices.Ownershippublic Websitehttps://www.zyxel.com ↗
SECURITY POSTURE

Zyxel has a poor security posture characterized by a high frequency of critical and high-severity vulnerabilities across its product line, particularly involving command injection and buffer overflow flaws in routers, firewalls, and NAS devices.

Notable failures
  • CVE-2017-6884 critical RCE in diagnostic tools
  • CVE-2024-11667 critical path traversal in web management
  • CVE-2024-40890 high RCE in DSL CPE devices
  • CVE-2023-27992 high pre-auth RCE in NAS devices
  • CVE-2023-33010 high buffer overflow in firewall ID processing
  • CVE-2020-29583 high hard-coded credentials in firewalls
Patterns: repeated unpatched command injection vulnerabilities; repeated buffer overflow vulnerabilities in firewall functions; pre-authentication RCEs in NAS and router devices
FAILURE HISTORY · 13
DATEEVENTSEVSUMMARY
2023-09-18 CVE-2017-6884 critical Zyxel EMG2926 routers suffered a critical command injection flaw in their diagnostic tools that allowed remote attackers to execute arbitrary commands.
2022-05-16 CVE-2022-30525 high Zyxel firewalls suffered a command injection flaw allowing attackers to execute arbitrary OS commands and modify files.
2022-03-25 CVE-2020-9054 high Zyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code.
2021-11-03 CVE-2020-29583 high Zyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account.
2024-12-03 CVE-2024-11667 critical Zyxel firewalls had a path traversal flaw in their web management interface that allowed attackers to upload or download files via crafted URLs.
2023-06-23 CVE-2023-27992 high Zyxel NAS devices vulnerable to remote command injection.
2023-06-05 CVE-2023-33010 high Zyxel Multiple Firewalls Buffer Overflow Vulnerability
2023-06-05 CVE-2023-33009 high Zyxel Multiple Firewalls Buffer Overflow Vulnerability
2023-05-31 CVE-2023-28771 high Zyxel firewalls allow remote command execution via crafted packets.
2025-02-11 CVE-2024-40890 high Zyxel DSL CPE devices have a command injection vulnerability actively exploited in the wild, allowing authenticated attackers to execute OS commands.
2025-02-11 CVE-2024-40891 high Zyxel DSL CPE devices have a command injection vulnerability exploitable via Telnet after authentication, allowing attackers to execute OS commands remotely.
2023-08-07 CVE-2017-18368 high Zyxel P660HN-T1A routers have a command injection vulnerability accessible to unauthenticated users, allowing remote code execution.
2024-11-27 CVE-2024-11667 high CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Zyxel's hard-coded credentials flaw is widely recognized as a severe, unchangeable vulnerability that left devices exposed to unauthorized access, reflecting poorly on the vendor's security posture an
cooey ↗severe-fallout-0.80
NVD entry confirms the flaw's severity and the unchangeable nature of the password, indicating a critical failure in vendor security design.
"Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ('zyfwp') with an unchangeable password."
cvefeed.io ↗severe-fallout+0.00
No direct commentary on Zyxel's handling; purely a CISA KEV catalog page.
NIST ↗severe-fallout+0.00
No direct commentary on Zyxel's handling; purely a government website homepage.
Dark Reading ↗severe-fallout+0.00
No direct commentary on Zyxel's handling; purely a news site homepage.
cybersecuritynews.com ↗severe-fallout+0.00
No direct commentary on Zyxel's handling; unrelated article about AI agents.
www.cvefind.com ↗severe-fallout+0.00
No direct commentary on Zyxel's handling; purely a database listing.
Open questions: Exact founding year and HQ location from web sources · Current employee count and organizational size · Specific remediation timelines for CVEs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:48:12.654157+00:00