<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Zyxel</title><description>Vulnerabilities in Zyxel ZyWALL/USG, USG FLEX, ATP, and VPN-series firewalls and other SMB/branch-office edge networking gear — perimeter appliances that recur on the CISA KEV catalog and remain a durable target for botnet operators years after patch availability. Combined article + CVE feed for the Zyxel beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2017-18368 — Zyxel P660HN-T1A Routers Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2017-18368/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-18368/</guid><description>Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-6884 — Zyxel EMG2926 Routers Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6884/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6884/</guid><description>Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>high</category><category>cve</category></item><item><title>CVE-2020-29583 — Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability</title><link>https://0daynews.com/cve/cve-2020-29583/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-29583/</guid><description>Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account (&quot;zyfwp&quot;) with an unchangeable password.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-9054 — Zyxel Multiple NAS Devices OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2020-9054/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-9054/</guid><description>Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-30525 — Zyxel Multiple Firewalls OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2022-30525/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-30525/</guid><description>A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-27992 — Zyxel Multiple NAS Devices Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-27992/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-27992/</guid><description>Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-28771 — Zyxel Firewall OS Command Injection</title><link>https://0daynews.com/cve/cve-2023-28771/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-28771/</guid><description>An OS command-injection vulnerability in multiple Zyxel firewall product lines allows an unauthenticated attacker to execute arbitrary commands by sending a crafted packet to the device. Exploited by Mirai-variant botnets shortly after disclosure.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-33009 — Zyxel Multiple Firewalls Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2023-33009/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-33009/</guid><description>Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-33010 — Zyxel Multiple Firewalls Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2023-33010/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-33010/</guid><description>Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-11667 — Zyxel Multiple Firewalls Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-11667/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-11667/</guid><description>Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>high</category><category>cve</category></item><item><title>CVE-2024-40890 — Zyxel DSL CPE OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-40890/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-40890/</guid><description>Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>high</category><category>cve</category></item><item><title>CVE-2024-40891 — Zyxel DSL CPE OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-40891/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-40891/</guid><description>Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>Zyxel</category><category>high</category><category>cve</category></item><item><title>Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch</title><link>https://0daynews.com/articles/2026-07-15-zyxel-cve-2023-28771-epss-099-three-years-post-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-zyxel-cve-2023-28771-epss-099-three-years-post-patch/</guid><description>Zyxel&apos;s 2023 firewall command-injection bug still ranks EPSS 0.99 three years post-patch. Scans stay constant; unpatched SMB perimeter boxes remain plentiful.</description><pubDate>Wed, 15 Jul 2026 17:15:00 GMT</pubDate><category>Zyxel</category><category>article</category></item></channel></rss>