Zyxel vulnerabilities
3 CVEs tracked
Zyxel appears in our reporting with a cluster of critical vulnerabilities across its product line. Key issues include a path traversal in CLI configuration file execution (CVE-2026-14818) affecting ATP/USG FLEX appliances, an authenticated command injection in PKCS#12 certificate export (CVE-2026-6837), and an authentication bypass in the WAX650S captive portal via social_login.cgi (CVE-2026-8508). Defenders should prioritize patching the affected firewall firmware versions and immediately review access controls on wireless devices.
Azərbaycanca: Hesabatlarımızda Zyxel zəifliklər baxımından aktiv şəkildə müşahidə olunur. Bu dövr ərzində üç kritik zəiflik aşkarlanıb: CLI konfiqurasiya faylı icrasında path traversal (CVE-2026-14818), authenticated kontekstdə command injection (CVE-2026-6837) və WLAN səviyyəsində captive portal autentifikasiyasından yan keçmə (CVE-2026-8508). Müdafiəçi tərəf xüsusilə ATP/USG FLEX seriyalı firewall-lar üçün buraxılmış firmware yeniləmələrini təcili tətbiq etməli, eyni zamanda WAX650S kimi simsiz cihazlarda əlçatanlıq nəzarətlərini gücləndirməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Zyxel: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.