Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.0%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+724/4/202317/6/2026
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp”…
ModificadaAlta (8.1)1.3%—Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+724/4/202317/6/2026
A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in…
ModificadaAlta (7.2)2.8%—Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+217/2/202317/6/2026
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an…
ModificadaAlta (7.4)0.57%—Netgear Wnr612v2 FirmwareNetgear Dgn1000v3 FirmwareNetgear D6100 FirmwareNetgear Wnr1000v2 Firmware+52/2/202317/6/2026
An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification.…
ModificadaMedia (6.1)0.39%—Zyxel Atp800 FirmwareZyxel Atp700 FirmwareZyxel Atp500 FirmwareZyxel Atp200 Firmware+156/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a…
ModificadaAlta (7.8)1.1%💥 ExploitZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+2119/7/202217/6/2026
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX 700 firmware versions 4.50 through 5.30, USG FLEX 50(W) firmware versions…
ModificadaMedia (6.5)1.4%—Zyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+2119/7/202217/6/2026
A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 firmware versions 4.50 through 5.30, USG FLEX 500 firmware versions 4.50 through 5.30, USG FLEX…
ModificadaAlta (7.5)1.3%—Siemens En100 Ethernet Module Dnp3 IP FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+112/7/202217/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaAlta (7.5)1.2%—Siemens En100 Ethernet Module Dnp3 FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+114/6/202217/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaAlta (7.8)4.8%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00…
ModificadaAlta (7.8)6.2%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+6124/5/202217/6/2026
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions…
ModificadaMedia (6.5)0.71%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+2824/5/202217/6/2026
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through…
ModificadaMedia (6.1)9.4%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+2824/5/202217/6/2026
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+1212/5/202217/6/2026
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W)…
ModificadaMedia (6.1)0.57%—Totolink N200re FirmwareTotolink N100re Firmware2/5/202217/6/2026
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
ModificadaCrítica (9.8)95%💥 ExploitZyxel Usg40 FirmwareZyxel Usg40w FirmwareZyxel Usg60 FirmwareZyxel Usg60w Firmware+1928/3/202217/6/2026
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through…
ModificadaCrítica (9.8)2.3%—Zyxel Usg1900 FirmwareZyxel Usg1100 FirmwareZyxel Usg310 FirmwareZyxel Usg210 Firmware+332/7/202117/6/2026
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
ModificadaAlta (8.8)2.3%—Askey Rtf3505vw-n1 BR SV G000 R3505vwn1001 S32 7 Firmware26/3/202117/6/2026
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execution as root.
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitZyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+2622/12/202017/6/2026
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
ModificadaAlta (8.8)4.2%—Totolink A3002r FirmwareTotolink A3002ru-v1 FirmwareTotolink A3002ru-v2 FirmwareTotolink A702r-v2 Firmware+99/12/202017/6/2026
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
ModificadaAlta (7.5)1.1%—Netgear Ac1450 FirmwareNetgear C6300 FirmwareNetgear D1500 FirmwareNetgear D3600 Firmware+3928/4/202017/6/2026
Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1500 before 2017-01-06, D3600 before 2017-01-06, D6000 before 2017-01-06, D6100 before 2017-01-06, D6200 before 2017-01-06, D6200B before 2017-01-06, D6300B before…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+234/3/202017/6/2026
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI…
ModificadaAlta (8.8)25%💥 ExploitTotolink A3002ru FirmwareTotolink A702r FirmwareTotolink N301rt FirmwareTotolink N302r Firmware+427/1/202017/6/2026
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through…
ModificadaAlta (7.5)6.4%💥 ExploitTotolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through…
ModificadaAlta (7.5)8.7%💥 ExploitTotolink A3002ru FirmwareTotolink A702r FirmwareTotolink N302r FirmwareTotolink N300rt Firmware+1427/1/202017/6/2026
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0,…
Orbitaley — Vulnerabilidades