Zyxel
Zyxel Nas542 Firmware: vulnerabilidades y CVE
Zyxel Nas542 Firmware tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas9
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-27992 | Crítica (9.8) | 83% | ⚠ Explotación activa | 19 jun 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to… |
| CVE-2020-9054 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 mar 2020 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6342 | Crítica (9.8) | 2.1% | — | 10 sept 2024 | **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an… |
| CVE-2024-29976 | Media (6.5) | 9.0% | — | 4 jun 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before… |
| CVE-2024-29975 | Media (6.7) | 0.47% | — | 4 jun 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before… |
| CVE-2024-29974 | Crítica (9.8) | 23% | — | 4 jun 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0… |
| CVE-2024-29973 | Crítica (9.8) | 86% | — | 4 jun 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow… |
| CVE-2024-29972 | Crítica (9.8) | 89% | — | 4 jun 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0… |
| CVE-2023-5372 | Alta (7.2) | 28% | — | 30 ene 2024 | The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with… |
| CVE-2023-4474 | Crítica (9.8) | 30% | — | 30 nov 2023 | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute… |
| CVE-2023-4473 | Crítica (9.8) | 41% | — | 30 nov 2023 | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating… |
| CVE-2023-37928 | Alta (8.8) | 60% | — | 30 nov 2023 | A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to… |
| CVE-2023-37927 | Alta (8.8) | 1.8% | — | 30 nov 2023 | The improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some… |
| CVE-2023-35138 | Crítica (9.8) | 40% | — | 30 nov 2023 | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker… |
| CVE-2023-35137 | Alta (7.5) | 0.87% | — | 30 nov 2023 | An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain… |
| CVE-2023-27992 | Crítica (9.8) | 83% | ⚠ Explotación activa | 19 jun 2023 | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to… |
| CVE-2023-27988 | Alta (7.2) | 1.4% | — | 30 may 2023 | The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating… |
| CVE-2020-13365 | Alta (8.8) | 0.97% | — | 6 ago 2020 | Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520… |
| CVE-2020-13364 | Alta (8.8) | 1.2% | — | 6 ago 2020 | A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and… |
| CVE-2020-9054 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 mar 2020 | Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zyxel
Gs1900-10hp Firmware · 35Cloudcnm Secumanager · 35USG Flex 100w Firmware · 34USG Flex 700 Firmware · 34USG Flex 500 Firmware · 34USG Flex 200 Firmware · 34USG Flex 100 Firmware · 30Emg3525-t50b Firmware · 28Vmg8623-t50b Firmware · 28Emg5523-t50b Firmware · 28USG Flex 50W Firmware · 26Atp500 Firmware · 25