zyxel
Security Risk Profile
48
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 354 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 14, 2001 to present
354
Total CVEs
206
Critical+High
17
Exploited
180
Unpatched
Threat Assessment
Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
180
Critical/High
Risk Level
48/100
medium
⚠️ 17 Active Exploits⚡ 10 Zero-Days
Severity Distribution
Critical
75High
131Medium
134Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
1<5%
27Age Distribution
Common Weaknesses (CWE)
1
OS Command Injection
64
2
Command Injection
56
3
Buffer Overflow
36
4
XSS
27
5
CSRF
14
Most Affected Products
1. Cisco IOS XE224
2. Zyxel Access Points Firmware154
3. Zyxel ZLD104
4. Zyxel Cloud CNM SecuManager70
5. Zyxel ZyNOS63
Recent Vulnerabilities
See more →CVE-2026-7273
CVSS 8.8high
6/16/2026🔧 No Patch
CVE-2026-3871
CVSS 6.5medium
6/2/2026🔧 No Patch
CVE-2026-3870
CVSS 6.5medium
6/2/2026🔧 No Patch
CVE-2026-4795
CVSS 6.5medium
5/26/2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1tlf7xf/zyxel_superadmin_credential_leak_expanded_from/
unknown
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
5/23/2026🔧 No Patch
https://reddit.com/r/netsec/comments/1tkkq0m/zyxel_lowpriv_account_leaked_superadmin_ftps_and/
unknown
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
5/22/2026🔧 No Patch
CVE-2026-7287
CVSS 7.5EPSS 0%high
5/12/2026🔧 No Patch
CVE-2026-7257
CVSS 4.4EPSS 0%medium
5/12/2026🔧 No Patch
CVE-2026-7256
CVSS 8.8EPSS 1%high
5/12/2026🔧 No Patch
CVE-2026-7255
CVSS 6.5EPSS 0%medium
5/12/2026🔧 No Patch
Monitor zyxel in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.