Zyxel
Zyxel Nas540 Firmware: vulnerabilidades y CVE
Zyxel Nas540 Firmware tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-27992 | Crítica (9.8) | 83% | ⚠ Explotación activa | 19 jun 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to… |
| CVE-2020-9054 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 mar 2020 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-27992 | Crítica (9.8) | 83% | ⚠ Explotación activa | 19 jun 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to… |
| CVE-2023-27988 | Alta (7.2) | 1.4% | — | 30 may 2023 | The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating… |
| CVE-2020-13365 | Alta (8.8) | 0.97% | — | 6 ago 2020 | Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520… |
| CVE-2020-13364 | Alta (8.8) | 1.2% | — | 6 ago 2020 | A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and… |
| CVE-2020-9054 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 mar 2020 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zyxel
Cloudcnm Secumanager · 35Gs1900-10hp Firmware · 35USG Flex 700 Firmware · 34USG Flex 500 Firmware · 34USG Flex 200 Firmware · 34USG Flex 100w Firmware · 34USG Flex 100 Firmware · 30Emg3525-t50b Firmware · 28Emg5523-t50b Firmware · 28Vmg8623-t50b Firmware · 28USG Flex 50W Firmware · 26Vmg3625-t50b Firmware · 25