Skip to content
eastbaycyber

Zyxel: CISA KEV History

Every Zyxel vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.

Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard

KEV entries
12
Added, last 12 months
0
Ransomware-linked
2
Latest addition
2025-02-11

Zyxel KEV additions per month, last 24 months

2024-10: 0 added24/102024-11: 0 added2024-12: 1 added12025-01: 0 added25/012025-02: 2 added22025-03: 0 added2025-04: 0 added25/042025-05: 0 added2025-06: 0 added2025-07: 0 added25/072025-08: 0 added2025-09: 0 added2025-10: 0 added25/102025-11: 0 added2025-12: 0 added2026-01: 0 added26/012026-02: 0 added2026-03: 0 added2026-04: 0 added26/042026-05: 0 added2026-06: 0 added2026-07: 0 added26/072026-08: 0 added2026-09: 0 added

Most-listed products: Multiple Firewalls, DSL CPE Devices, Multiple Network-Attached Storage (NAS) Devices, EMG2926 Routers, P660HN-T1A Routers.

Latest 12 of 12 Zyxel KEV entries

CVEVulnerabilityAddedRansomware
CVE-2024-40891Zyxel DSL CPE OS Command Injection Vulnerability2025-02-11No
CVE-2024-40890Zyxel DSL CPE OS Command Injection Vulnerability2025-02-11No
CVE-2024-11667Zyxel Multiple Firewalls Path Traversal Vulnerability2024-12-03Yes
CVE-2017-6884Zyxel EMG2926 Routers Command Injection Vulnerability2023-09-18Yes
CVE-2017-18368Zyxel P660HN-T1A Routers Command Injection Vulnerability2023-08-07No
CVE-2023-27992Zyxel Multiple NAS Devices Command Injection Vulnerability2023-06-23No
CVE-2023-33009Zyxel Multiple Firewalls Buffer Overflow Vulnerability2023-06-05No
CVE-2023-33010Zyxel Multiple Firewalls Buffer Overflow Vulnerability2023-06-05No
CVE-2023-28771Zyxel Multiple Firewalls OS Command Injection Vulnerability2023-05-31No
CVE-2022-30525Zyxel Multiple Firewalls OS Command Injection Vulnerability2022-05-16No
CVE-2020-9054Zyxel Multiple NAS Devices OS Command Injection Vulnerability2022-03-25No
CVE-2020-29583Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability2021-11-03No

CVE links go to our explainer when one exists, otherwise to the NVD record.

Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.