Report a Security Vulnerability

Report a Security Vulnerability
Report a Security Vulnerability

Zyxel cares about your network security. It’s our highest priority, and we want to work with you.

When submitting a security vulnerability report, reporters must provide the information listed below. Reports based solely on firmware reverse engineering, static analysis, or emulation environments are not eligible for assessment. To be considered for assessment, a report must be written in English, include all mandatory information, be based on the latest firmware or software version, and demonstrate the vulnerability on an affected physical device.

Mandatory Information

1. The affected product model(s), including the applicable firmware and/or software version(s)
2. A detailed description of the vulnerability, including its potential security impact
3. An estimated severity rating, such as a CVSS v3.1 score
4. Sufficient step-by-step instructions to reproduce the vulnerability
5. Proof-of-concept (PoC) code or an exploit demonstrating the vulnerability and its impact
6. Clear supporting evidence—such as screenshots, logs, or video—demonstrating that the PoC is valid and confirming the vulnerability’s impact on an affected physical device

Optional Information

1. Recommended remediation or mitigation measures
2. Relevant vulnerability classifications, including applicable Common Weakness Enumeration (CWE) identifiers

Note: Zyxel does not offer bug bounty or reward programs for reported vulnerabilities.