Zyxel known exploited vulnerabilities
CISA lists 13 Zyxel CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-09-21), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-9054 (Multiple Network-Attached Storage (NAS) Devices): EPSS 100.0%, added 2022-03-25
- CVE-2022-30525 (Multiple Firewalls): EPSS 99.9%, added 2022-05-16
- CVE-2023-28771 (Multiple Firewalls): EPSS 99.3%, added 2023-05-31
- CVE-2017-18368 (P660HN-T1A Routers): EPSS 94.4%, added 2023-08-07
- CVE-2020-29583 (Multiple Products): EPSS 90.2%, added 2021-11-03
Most affected Zyxel products
Multiple Firewalls (5), DSL CPE Devices (2), Multiple Network-Attached Storage (NAS) Devices (2), GS1900 Series Switches (1), EMG2926 Routers (1), P660HN-T1A Routers (1), Multiple Products (1).
All Zyxel CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-7273 | GS1900 Series Switches | GS1900 Series Switches Stack-Based Buffer Overflow | 2026-09-21 | 2026-09-24 | 2.5% | – |
| CVE-2024-40891 | DSL CPE Devices | DSL CPE OS Command Injection | 2025-02-11 | 2025-03-04 | 21.5% | – |
| CVE-2024-40890 | DSL CPE Devices | DSL CPE OS Command Injection | 2025-02-11 | 2025-03-04 | 20.7% | – |
| CVE-2024-11667 | Multiple Firewalls | Multiple Firewalls Path Traversal | 2024-12-03 | 2024-12-24 | 2.9% | Yes |
| CVE-2017-6884 | EMG2926 Routers | EMG2926 Routers Command Injection | 2023-09-18 | 2023-10-09 | 34.4% | Yes |
| CVE-2017-18368 | P660HN-T1A Routers | P660HN-T1A Routers Command Injection | 2023-08-07 | 2023-08-28 | 94.4% | – |
| CVE-2023-27992 | Multiple Network-Attached Storage (NAS) Devices | Multiple NAS Devices Command Injection | 2023-06-23 | 2023-07-14 | 82.8% | – |
| CVE-2023-33010 | Multiple Firewalls | Multiple Firewalls Buffer Overflow | 2023-06-05 | 2023-06-26 | 28.8% | – |
| CVE-2023-33009 | Multiple Firewalls | Multiple Firewalls Buffer Overflow | 2023-06-05 | 2023-06-26 | 28.1% | – |
| CVE-2023-28771 | Multiple Firewalls | Multiple Firewalls OS Command Injection | 2023-05-31 | 2023-06-21 | 99.3% | – |
| CVE-2022-30525 | Multiple Firewalls | Multiple Firewalls OS Command Injection | 2022-05-16 | 2022-06-06 | 99.9% | – |
| CVE-2020-9054 | Multiple Network-Attached Storage (NAS) Devices | Multiple NAS Devices OS Command Injection | 2022-03-25 | 2022-04-15 | 100.0% | – |
| CVE-2020-29583 | Multiple Products | Multiple Products Use of Hard-Coded Credentials | 2021-11-03 | 2022-05-03 | 90.2% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors