Product
zyxel zld
21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-9133
CVE-2025-8078
CVE-2024-11667
CVE-2024-42061
CVE-2024-7203
CVE-2024-6343
CVE-2024-42060
CVE-2024-42059
CVE-2024-42058
CVE-2024-42057
CVE-2023-5960
CVE-2023-5797
CVE-2023-5650
CVE-2023-4398
CVE-2023-4397
CVE-2023-37926
CVE-2023-37925
CVE-2023-35139
CVE-2023-35136
CVE-2020-29299
CVE-2020-25014
>= 4.32 and < 5.41
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware ver
>= 4.32 and < 5.41
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX ser
>= 5.00 and <= 5.38
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG
>= 4.32 and < 5.39
A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions
>= 4.60 and < 5.39
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX
>= 4.32 and < 5.39
A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series
>= 4.32 and < 5.39
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX ser
>= 5.00 and < 5.39
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX ser
>= 4.32 and < 5.39
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware
>= 4.32 and < 5.39
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLE
>= 4.50 and <= 5.37
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through
>= 4.32 and <= 5.37
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.3
>= 4.32 and <= 5.37
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX s
>= 4.32 and <= 5.37
An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series
all versions
A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(
>= 4.32 and <= 5.37
A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.5
>= 4.32 and <= 5.37
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.3
>= 5.10 and <= 5.37
A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.37, USG FLE
>= 4.32 and <= 5.37
An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37
< 4.39
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. Thi
>= 4.30 and <= 4.55
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 throug