z
zyxel
Security Risk Profile
51
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 360 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 14, 2001 to present
360
Total CVEs
209
Critical+High
17
Exploited
183
Unpatched
Threat Assessment
Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
183
Critical/High
Risk Level
51/100
medium
⚠️ 17 Active Exploits⚡ 10 Zero-Days🆕 2Fresh (<7d)📈 6 in Last 30 Days
Severity Distribution
Critical
75High
134Medium
135Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
1<5%
27Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
65
2
Command Injection
57
3
Buffer Overflow
36
4
XSS
27
5
CSRF
14
Most Affected Products
1. Cisco IOS XE224
2. Zyxel Access Points Firmware154
3. Zyxel ZLD104
4. Zyxel Cloud CNM SecuManager70
5. Zyxel ZyNOS63
Recent Vulnerabilities
See more →https://reddit.com/r/netsec/comments/1vq55y4/cve20266837_command_injection_in_zyxel_exportcgi/
unknown
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling
8/16/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1vq55rw/cve20266837_root_command_injection_affecting_18/
unknown
CVE-2026-6837: Root Command Injection Affecting 18 Zyxel Access Point Models
8/16/2026🔧 No Patch
CVE-2026-12984
CVSS 8.2high
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
8/10/2026🔧 No Patch
CVE-2026-14818
CVSS 7.2high
8/4/2026🔧 No Patch
CVE-2026-8508
CVSS 6.5medium
8/4/2026🔧 No Patch
CVE-2026-6837
CVSS 7.2high
8/4/2026🔧 No Patch
CVE-2026-7273
CVSS 8.8high
6/16/2026🔧 No Patch
CVE-2026-3871
CVSS 6.5medium
6/2/2026🔧 No Patch
CVE-2026-3870
CVSS 6.5medium
6/2/2026🔧 No Patch
CVE-2026-4795
CVSS 6.5medium
5/26/2026🔧 No Patch
Monitor zyxel in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.