Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)1.2%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)0.81%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service…
AplazadaAlta (7.1)0.19%—Zyxel PrestigeAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Prestige prestige allows Reflected XSS.This issue affects Prestige: from n/a through < 1.4.1.
AplazadaCrítica (9.8)0.39%—Zyxel PrestigeAI20/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.
AplazadaAlta (7.2)1.4%—Zyxel ATPAIZyxel USG FlexAIZyxel USG Flex 50AIZyxel Usg20 VPNAI5/2/202617/6/2026
A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.41, USG FLEX series firmware versions from V5.35 through V5.41, USG FLEX 50(W) series firmware versions from V5.35 through V5.41, and USG20(W)-VPN series…
AnalizadaAlta (8.8)1.1%—Zyxel Dm4200-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+5018/11/202517/6/2026
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
AnalizadaAlta (7.5)0.31%—Zyxel Lte3301-plus FirmwareZyxel Nr5103 FirmwareZyxel Nr5103e FirmwareZyxel Nr5309 Firmware+6218/11/202517/6/2026
An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web…
AnalizadaAlta (8.1)5.5%—Zyxel ZLD21/10/202517/6/2026
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could allow a…
AnalizadaAlta (7.2)1.4%—Zyxel ZLD21/10/202517/6/2026
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through V5.40, and USG20(W)-VPN series firmware versions from V4.16 through V5.40 could…
AnalizadaCrítica (9.8)0.59%—Zyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k FirmwareZyxel Emg6726-b10a Firmware+2016/7/202517/6/2026
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request.
AnalizadaAlta (7.2)0.57%—Zyxel Nwa50ax FirmwareZyxel Nwa50ax PRO FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+1915/7/202517/6/2026
A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific directories and delete files, such as the configuration file, on the affected device.
AplazadaCrítica (9.3)0.56%—Zyxel Wgs-80hpt-v2AIZyxel Wgs-4215-8t2sAI24/4/202517/6/2026
WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.
AnalizadaMedia (4.9)13%—Zyxel Amg1302-t10b Firmware22/4/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.
AnalizadaMedia (6.7)0.20%—Zyxel UOS22/4/202517/6/2026
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable device.
AnalizadaAlta (7.8)0.94%💥 ExploitZyxel UOS22/4/202517/6/2026
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or…
AnalizadaAlta (7.2)1.1%—Zyxel Wx5610-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+3711/3/202517/6/2026
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaAlta (7.2)1.1%—Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+3411/3/202517/6/2026
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaAlta (7.2)1.1%—Zyxel Emg5723-t50k FirmwareZyxel Dm4200-b0 FirmwareZyxel Vmg3927-t50k FirmwareZyxel Vmg4005-b50a Firmware+211/3/202517/6/2026
A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware version V5.50(ABOM.8.5)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaCrítica (9.8)14%💥 PoCZyxel Vmg4325-b10a FirmwareZyxel Sbg3500-n000 FirmwareZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b Firmware+104/2/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
AnalizadaAlta (8.8)22%⚠ Explotación activa💥 PoCZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+104/2/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
AnalizadaAlta (8.8)21%⚠ Explotación activaZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+104/2/202517/6/2026
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST…
AnalizadaAlta (8.8)0.54%—Zyxel Nwa50ax FirmwareZyxel Nwa50ax PRO FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+1914/1/202517/6/2026
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them…
AnalizadaAlta (7.2)1.2%—Zyxel Emg6726-b10a FirmwareZyxel Vmg3927-b50b FirmwareZyxel Vmg4005-b50a FirmwareZyxel Vmg4005-b60a Firmware+23/12/202417/6/2026
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaMedia (4.9)0.51%—Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+323/12/202417/6/2026
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management…
AnalizadaAlta (7.5)0.52%—Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7480-m804 Firmware+593/12/202417/6/2026
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a…