FAIL › dossier
Zyxel
VENDOR· dossier confidence 40%
Zyxel is a Taiwanese network security hardware vendor with a documented history of releasing products containing critical and high-severity vulnerabilities, including command injection and buffer overflow flaws in routers, firewalls, and NAS devices. The company's security posture is characterized by a high frequency of CVEs that require patching, indicating a need for rigorous internal security testing and vulnerability management.
PROFILE
Categorynetwork security hardwareWhat they doZyxel Group Corp designs and manufactures network security hardware, including routers, firewalls, and network-attached storage devices.Ownershippublic
Websitehttps://www.zyxel.com ↗
SECURITY POSTURE
Zyxel has a poor security posture characterized by a high frequency of critical and high-severity vulnerabilities across its product line, particularly involving command injection and buffer overflow flaws in routers, firewalls, and NAS devices.
Notable failures
- CVE-2017-6884 critical RCE in diagnostic tools
- CVE-2024-11667 critical path traversal in web management
- CVE-2024-40890 high RCE in DSL CPE devices
- CVE-2023-27992 high pre-auth RCE in NAS devices
- CVE-2023-33010 high buffer overflow in firewall ID processing
- CVE-2020-29583 high hard-coded credentials in firewalls
Patterns: repeated unpatched command injection vulnerabilities; repeated buffer overflow vulnerabilities in firewall functions; pre-authentication RCEs in NAS and router devices
FAILURE HISTORY · 13
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-09-18 | CVE-2017-6884 | critical | Zyxel EMG2926 routers suffered a critical command injection flaw in their diagnostic tools that allowed remote attackers to execute arbitrary commands. |
| 2022-05-16 | CVE-2022-30525 | high | Zyxel firewalls suffered a command injection flaw allowing attackers to execute arbitrary OS commands and modify files. |
| 2022-03-25 | CVE-2020-9054 | high | Zyxel NAS devices had a pre-auth command injection flaw allowing remote attackers to run arbitrary code. |
| 2021-11-03 | CVE-2020-29583 | high | Zyxel firewalls and AP controllers shipped with an unchangeable hard-coded credential in an undocumented account. |
| 2024-12-03 | CVE-2024-11667 | critical | Zyxel firewalls had a path traversal flaw in their web management interface that allowed attackers to upload or download files via crafted URLs. |
| 2023-06-23 | CVE-2023-27992 | high | Zyxel NAS devices vulnerable to remote command injection. |
| 2023-06-05 | CVE-2023-33010 | high | Zyxel Multiple Firewalls Buffer Overflow Vulnerability |
| 2023-06-05 | CVE-2023-33009 | high | Zyxel Multiple Firewalls Buffer Overflow Vulnerability |
| 2023-05-31 | CVE-2023-28771 | high | Zyxel firewalls allow remote command execution via crafted packets. |
| 2025-02-11 | CVE-2024-40890 | high | Zyxel DSL CPE devices have a command injection vulnerability actively exploited in the wild, allowing authenticated attackers to execute OS commands. |
| 2025-02-11 | CVE-2024-40891 | high | Zyxel DSL CPE devices have a command injection vulnerability exploitable via Telnet after authentication, allowing attackers to execute OS commands remotely. |
| 2023-08-07 | CVE-2017-18368 | high | Zyxel P660HN-T1A routers have a command injection vulnerability accessible to unauthenticated users, allowing remote code execution. |
| 2024-11-27 | CVE-2024-11667 | high | CVE-2024-11667: A directory traversal vulnerability in the web management interface of Zyxel ATP |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Zyxel's hard-coded credentials flaw is widely recognized as a severe, unchangeable vulnerability that left devices exposed to unauthorized access, reflecting poorly on the vendor's security posture an
NVD entry confirms the flaw's severity and the unchangeable nature of the password, indicating a critical failure in vendor security design.
"Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ('zyfwp') with an unchangeable password."
No direct commentary on Zyxel's handling; purely a CISA KEV catalog page.
No direct commentary on Zyxel's handling; purely a government website homepage.
No direct commentary on Zyxel's handling; purely a news site homepage.
No direct commentary on Zyxel's handling; unrelated article about AI agents.
No direct commentary on Zyxel's handling; purely a database listing.
DOSSIER SOURCES
- Zyxel Group Corp, 3704:TAI profile - FT.com - Financial Times · markets.ft.com
- Zyxel Group Corp, 3704:TAI summary - FT.com - Financial Times · markets.ft.com
- Asus - Wikipedia · en.wikipedia.org
- Zyxel Group Corp, 3704:TAI profile - FT.com - Financial Times · markets.ft.com
- Amazon (company) - Wikipedia · en.wikipedia.org
- Time.is - exact time, any time zone · time.is
Open questions: Exact founding year and HQ location from web sources · Current employee count and organizational size · Specific remediation timelines for CVEs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:48:12.654157+00:00