← Vulnerability feed

Vulnerability record · CVE-2018-9129 · published 15 August 2018

CVE-2018-9129: Zyxel zywall 110 firmware vulnerability

Zyxel · Zywall 110 Firmware

ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.

5.9 CVSS 3.0 Medium EPSS 0.97% · top 39.4%
5.9CVSS 3.0 base score, v2 4.3
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9129 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-33009Zyxel firewall notification function buffer overflowA buffer overflow in the notification function of multiple Zyxel firewall and VPN firmware lines (ATP, USG FLEX, USG20(W)-VPN, VPN, ZyWALL/USG) allow…KEVEPSS 28%analysed9.8CVE-2023-33010Zyxel firewall ID processing buffer overflow allows unauthenticated RCEA classic buffer overflow (CWE-120) exists in the ID processing function of multiple Zyxel firewall firmware lines, including ATP, USG FLEX, USG20(W)…KEVEPSS 29%analysed8.8CVE-2023-33011Zyxel usg 2200-vpn firmware vulnerabilityA format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.3…EPSS 0.34%8.8CVE-2023-33012Zyxel usg 20w-vpn firmware os command injection vulnerabilityA command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series fi…EPSS 9.9%8.8CVE-2023-28767Zyxel usg 2200-vpn firmware os command injection vulnerabilityThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmwar…EPSS 0.40%8.8CVE-2023-27991Zyxel atp200 firmware os command injection vulnerabilityThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f…EPSS 1.5%8.1CVE-2023-22916Zyxel usg flex 100 firmware improper input validation vulnerabilityThe configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W)…EPSS 0.69%8.0CVE-2023-34138Zyxel usg 20w-vpn firmware os command injection vulnerabilityA command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX ser…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2018-9129), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.