Skip to main content

Zyxel security briefs

2 published alerts for Zyxel products and services.

Actively exploited (KEV)Ransomware

CVE-2024-11667

Zyxel Multiple Firewalls Path Traversal Vulnerability

Zyxel Multiple Firewalls is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-11667). Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. CISA remediation due date: 2024-12-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-6884

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 Routers is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-6884). Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. CISA remediation due date: 2023-10-09. If you need help checking exposure, call (864) 335-9223.