Security advisories
PSIRT Policy
The Zyxel Product Security Incident Response Team (PSIRT) responds to vulnerability reports, investigates the reported vulnerabilities, and implements the best course of action to protect our customers. We help you build trust with your customers by making network security our highest priority. It’s what drives us to deliver timely, actionable advice on emerging vulnerabilities. Zyxel is authorized as a CVE Numbering Authority (CNA). This recognizes our commitment to security disclosures and a continuous enhancement of vulnerability reporting.
Report Vulnerability
When submitting a security vulnerability report, reporters must provide the information listed below. Reports based solely on firmware reverse engineering, static analysis, or emulation environments are not eligible for assessment. To be considered for assessment, a report must be written in English, include all mandatory information, be based on the latest firmware or software version, and demonstrate the vulnerability on an affected physical device.
Mandatory Information
- The affected product model(s), including the applicable firmware and/or software version(s)
- A detailed description of the vulnerability, including its potential security impact
- An estimated severity rating, such as a CVSS v3.1 score
- Sufficient step-by-step instructions to reproduce the vulnerability
- Proof-of-concept (PoC) code or an exploit demonstrating the vulnerability and its impact
- Clear supporting evidence—such as screenshots, logs, or video—demonstrating that the PoC is valid and confirming the vulnerability’s impact on an affected physical device
Optional Information
- Recommended remediation or mitigation measures
- Relevant vulnerability classifications, including applicable Common Weakness Enumeration (CWE) identifiers
Note: Zyxel does not offer bug bounty or reward programs for reported vulnerabilities.
Advisories
Zyxel security advisory for command injection vulnerability in P660HN-T1A DSL CPE
Zyxel security advisory for security misconfiguration vulnerability of 4G LTE indoor routers
Zyxel security advisory for DoS vulnerability of switches
Zyxel security advisory for cleartext storage of information vulnerability
Zyxel security advisory for buffer overflow vulnerability in Realtek eCos SDK
Zyxel security advisory for OS command injection and buffer overflow vulnerabilities of CPE and ONTs
Zyxel security advisory for multiple vulnerabilities
Zyxel security advisory for Apache Log4j RCE vulnerabilities
Zyxel security advisory for FragAttacks against Wi-Fi products
Zyxel security advisory for CGI vulnerability of LTE
Zyxel security advisory for DNSpooq
Zyxel security advisory for a new variant of Gafgyt malware
Zyxel security advisory for P1302-T10D v3 modem insecure direct object reference vulnerability
Zyxel security advisory for the new Mirai malware variant targeting P660HN devices
Reinforcing router security: German BSI’s Secure Broadband Router guideline
Zyxel security advisory for BCMUPnP_Hunter botnet
Zyxel security advisory for IKEv1 protocol vulnerability
Zyxel security advisory for the Linux kernel TCP flaw
Security update for Zyxel CPE devices and Small Business Gateways
Security advisory for the VPNFilter malware
Zyxel security advisory for Denial of Service on P-660HW v3
Zyxel security advisory for Meltdown and Spectre attacks
Zyxel security advisory for the recent botnet attacks targeting PK5001Z
Zyxel security advisory for dnsmasq vulnerabilities
Zyxel statement to vulnerability CVE-2017-3216
Zyxel advisory: password change recommendations to maximize protection
Zyxel statement for the TR-064 protocol implementation in CPEs
Brute force attacks? Zyxel to tighten protection on routers and CPE
Zyxel advisory for vulnerability CVE-2015-7547
Zyxel to fix SSH private Key and certificate vulnerability
Zyxel to issue fix for CERT VU#870744 Vulnerabilities
Zyxel to issue fix for LTE3301-Q222 software bug
Zyxel not affected by “RSA-CRT Key Leaks”
Zyxel product support for Microsoft Windows 10
Guard against “Misfortune Cookie” vulnerability
Shellshock!? Is it an issue for Zyxel products?
Zyxel security advisory for OS command injection and buffer overflow vulnerabilities of CPE and ONTs
Zyxel security advisory for multiple vulnerabilities
Zyxel security advisory for Apache Log4j RCE vulnerabilities
Zyxel security advisory for FragAttacks against WiFi products
Zyxel security advisory for CGI vulnerability of LTE
Zyxel security advisory for DNSpooq
Zyxel security advisory for a new variant of Gafgyt malware
Zyxel security advisory for P1302-T10D v3 modem insecure direct object reference vulnerability
Zyxel security advisory for the new Mirai malware variant targeting P660HN devices
Reinforcing router security: German BSI’s Secure Broadband Router guideline
Zyxel security advisory for BCMUPnP_Hunter botnet
Zyxel security advisory for IKEv1 protocol vulnerability
Zyxel security advisory for the Linux kernel TCP flaw
Security update for Zyxel CPE devices and Small Business Gateways
Security advisory for the VPNFilter malware
Zyxel security advisory for Denial of Service on P-660HW v3
Zyxel security advisory for Meltdown and Spectre attacks
Zyxel security advisory for the recent botnet attacks targeting PK5001Z
Zyxel security advisory for dnsmasq vulnerabilities
Zyxel statement to vulnerability CVE-2017-3216
Zyxel advisory: password change recommendations to maximize protection
Zyxel statement for the TR-064 protocol implementation in CPEs
Brute force attacks? Zyxel to tighten protection on routers and CPE
Zyxel advisory for vulnerability CVE-2015-7547
Zyxel to fix SSH private Key and certificate vulnerability
Zyxel to issue fix for CERT VU#870744 Vulnerabilities
Zyxel to issue fix for LTE3301-Q222 software bug
Zyxel not affected by “RSA-CRT Key Leaks”
Zyxel product support for Microsoft Windows 10
Guard against “Misfortune Cookie” vulnerability
Shellshock!? Is it an issue for Zyxel products?