Zyxel: CISA KEV History
Every Zyxel vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.
Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard
KEV entries
12
Added, last 12 months
0
Ransomware-linked
2
Latest addition
2025-02-11
Zyxel KEV additions per month, last 24 months
Most-listed products: Multiple Firewalls, DSL CPE Devices, Multiple Network-Attached Storage (NAS) Devices, EMG2926 Routers, P660HN-T1A Routers.
Latest 12 of 12 Zyxel KEV entries
| CVE | Vulnerability | Added | Ransomware |
|---|---|---|---|
| CVE-2024-40891 | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | No |
| CVE-2024-40890 | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | No |
| CVE-2024-11667 | Zyxel Multiple Firewalls Path Traversal Vulnerability | 2024-12-03 | Yes |
| CVE-2017-6884 | Zyxel EMG2926 Routers Command Injection Vulnerability | 2023-09-18 | Yes |
| CVE-2017-18368 | Zyxel P660HN-T1A Routers Command Injection Vulnerability | 2023-08-07 | No |
| CVE-2023-27992 | Zyxel Multiple NAS Devices Command Injection Vulnerability | 2023-06-23 | No |
| CVE-2023-33009 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 2023-06-05 | No |
| CVE-2023-33010 | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 2023-06-05 | No |
| CVE-2023-28771 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | 2023-05-31 | No |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability | 2022-05-16 | No |
| CVE-2020-9054 | Zyxel Multiple NAS Devices OS Command Injection Vulnerability | 2022-03-25 | No |
| CVE-2020-29583 | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability | 2021-11-03 | No |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.