CVE-2020-29299: Zyxel Nsg Firmware

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.

Affected products

  • Zyxel Nsg Firmware: before 1.33 (fixed in 1.33); version 1.33 only
  • Zyxel Usg Flex Firmware: affected versions not specified
  • Zyxel VPN Orchestrator: before 10.03 (fixed in 10.03)
  • Zyxel Zld: before 4.39 (fixed in 4.39); before 4.55 (fixed in 4.55)

Published 2020-12-27. Last modified 2026-06-17.