Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-7273 | Zyxel | GS1900 Series Switches | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | 8.8 CNA | 2026-09-21 | 2026-09-24 | Unknown |
| CVE-2024-40890 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. | 8.8 CNA | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-40891 | Zyxel | DSL CPE Devices | Zyxel DSL CPE OS Command Injection Vulnerability Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. | 8.8 CNA | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-11667 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Path Traversal Vulnerability Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. | 7.5 CNA | 2024-12-03 | 2024-12-24 | Known |
| CVE-2017-6884 | Zyxel | EMG2926 Routers | Zyxel EMG2926 Routers Command Injection Vulnerability Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | 8.8 CISA | 2023-09-18 | 2023-10-09 | Known |
| CVE-2017-18368 | Zyxel | P660HN-T1A Routers | Zyxel P660HN-T1A Routers Command Injection Vulnerability Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. | 9.8 CISA | 2023-08-07 | 2023-08-28 | Unknown |
| CVE-2023-27992 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. | 9.8 CNA | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-33010 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | 9.8 CNA | 2023-06-05 | 2023-06-26 | Unknown |
| CVE-2023-33009 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls Buffer Overflow Vulnerability Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. | 9.8 CNA | 2023-06-05 | 2023-06-26 | Unknown |
| CVE-2023-28771 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection Vulnerability Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. | 9.8 CNA | 2023-05-31 | 2023-06-21 | Unknown |
| CVE-2022-30525 | Zyxel | Multiple Firewalls | Zyxel Multiple Firewalls OS Command Injection Vulnerability A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device. | 9.8 CNA | 2022-05-16 | 2022-06-06 | Unknown |
| CVE-2020-9054 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | Zyxel Multiple NAS Devices OS Command Injection Vulnerability Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. | 9.8 CISA | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-29583 | Zyxel | Multiple Products | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |