Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
346 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.4% | — | Zyxel Nsa325 V2 Firmware | 27/11/2018 | 17/6/2026 | A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API. | |
| Modificada | Alta (8.8) | 0.88% | — | Zyxel Nsa325 V2 Firmware | 27/11/2018 | 17/6/2026 | Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Zyxel Vmg1312-b10d Firmware | 17/11/2018 | 17/6/2026 | Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. | |
| Modificada | Alta (8.8) | 0.49% | — | Zyxel Zywall USG 100 Firmware | 10/11/2018 | 17/6/2026 | ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS. | |
| Modificada | Crítica (9.8) | 1.1% | — | Zyxel Vmg3312-b10b Firmware | 29/10/2018 | 17/6/2026 | ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. | |
| Modificada | Media (6.1) | 0.80% | — | Zyxel Vmg3312 B10b Firmware | 26/8/2018 | 17/6/2026 | Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter. | |
| Modificada | Media (5.9) | 0.97% | — | Zyxel Zywall 110 FirmwareZyxel Zywall 1100 FirmwareZyxel Zywall 310 FirmwareZyxel Zywall VPN 50 Firmware+13 | 15/8/2018 | 17/6/2026 | ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections. | |
| Modificada | Media (6.8) | 0.46% | — | Zyxel Ac3000 Firmware | 1/4/2018 | 17/6/2026 | The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system. Furthermore, an attacker can start the… | |
| Modificada | Crítica (9.8) | 4.0% | — | Zyxel P-870h-51 Firmware | 21/2/2018 | 17/6/2026 | This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by… | |
| Modificada | Alta (7.5) | 1.7% | — | Zyxel P-660hw V3 Firmware | 16/1/2018 | 17/6/2026 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets. | |
| Modificada | Alta (7.5) | 2.3% | — | Zyxel P-660hw Firmware | 29/12/2017 | 17/6/2026 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1. | |
| Modificada | Crítica (9.8) | 2.2% | — | Zyxel Nbg6716 Firmware | 10/10/2017 | 17/6/2026 | Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call. | |
| Modificada | Media (5.9) | 0.79% | — | Zyxel Nwa1100-n FirmwareZyxel Nwa1100-nh FirmwareZyxel Nwa1121-ni FirmwareZyxel Nwa1123-ac Firmware+21 | 28/9/2017 | 17/6/2026 | ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business… | |
| Modificada | Alta (8.8) | 12% | 💥 Exploit | Zyxel Pk5001z Firmware | 25/7/2017 | 17/6/2026 | ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices). | |
| Modificada | Crítica (9.8) | 5.2% | — | Greenpacket Ox350 FirmwareHuawei Bm2022 FirmwareHuawei Hes-309m FirmwareHuawei Hes-319m Firmware+10 | 20/6/2017 | 17/6/2026 | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request. | |
| Modificada | Crítica (10) | 2.5% | — | Zyxel Wre6505 Firmware | 19/4/2017 | 17/6/2026 | Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process. | |
| Analizada | Alta (8.8) | 35% | ⚠ Explotación activa💥 Exploit | Zyxel Emg2926 Firmware | 6/4/2017 | 1/10/2026 | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip… | |
| Modificada | Alta (7.5) | 2.1% | — | Zyxel Usg50 FirmwareZyxel Nwa3560-n Firmware | 21/2/2017 | 17/6/2026 | Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets. | |
| Modificada | Media (5.9) | 1.6% | — | Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareSamsung X14j FirmwareZyxel Gs1900-10hp Firmware+1 | 6/4/2016 | 17/6/2026 | The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673. | |
| Modificada | Alta (7.5) | 2.7% | — | SUN OpensolarisZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware | 6/4/2016 | 17/6/2026 | Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an… | |
| Modificada | Alta (7.5) | 1.9% | — | Dell EMC Powerscale OnefsNetgear Jr6150 FirmwareZyxel Gs1900-10hp FirmwareZzinc Keymouse Firmware | 6/4/2016 | 17/6/2026 | Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348. | |
| Modificada | Alta (7.5) | 3.3% | — | Cisco IOS XELenovo Thinkcentre E75s FirmwareSamsung X14j FirmwareSUN Opensolaris+2 | 26/3/2016 | 17/6/2026 | Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293. | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco IOS XEIntel Core I5-9400f FirmwareNetgear Jr6150 FirmwareSamsung X14j Firmware+3 | 26/3/2016 | 17/6/2026 | The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410. | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco IOS XENetgear Jr6150 FirmwareSamsung X14j FirmwareSUN Opensolaris+2 | 26/3/2016 | 17/6/2026 | Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821. | |
| Modificada | Media (5.9) | 3.0% | — | Cisco IOS XELenovo Thinkcentre E75s FirmwareNetgear Jr6150 FirmwareSamsung X14j Firmware+3 | 26/3/2016 | 17/6/2026 | The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417. |