CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Zyxel security advisory (AV26-780)

unknown
Serial number: AV26-780 Date: August 5, 2026 As of August 4, 2026, Zyxel is affected by vulnerabilities in the following products: ATP series firmware from V4.32 through V5.42 Patch 1 USG FLEX 50(W) series firmware from V4.16 through V5.42 Patch 1 USG FLEX series firmware from V4.50 through V5.42 Patch 1 USG20(W)-VPN series firmware from V4.16 through V5.42 Patch 1 WAX650S firmware Prior to or equal to 7.10(ABRM.4)C0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers | Zyxel Networks

CSIRTS triage

vendor: Zyxelproduct: Firewall and Access Point FirmwarePath traversalCode injectionAuthentication bypassaffected: ATP series V4.32–V5.42 Patch 1; USG FLEX 50(W) V4.16–V5.42 Patch 1; USG FLEX V4.50–V5.42 Patch 1; USG20(W)-VPN V4.16–V5.42 Patch 1; WAX650S ≤7.10(ABRM.4)C0
What
Path traversal in configuration file execution, command injection, and improper authentication in ZLD firewalls and security routers.
Who is affected
Zyxel ATP, USG FLEX, USG20(W)-VPN, and WAX650S deployments running affected firmware versions globally.
Urgency
High urgency; path traversal and command injection enable unauthorized configuration access and remote code execution.
Action
Apply available firmware patches for each product line to versions after V5.42 Patch 1 (ATP/USG) or after 7.10(ABRM.4)C0 (WAX650S).

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Firewall and Access Point Firmware

Get an email when a new Firewall and Access Point Firmware advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/zyxel-security-advisory-av26-780

More from Canadian Centre for Cyber Security