Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
346 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.9% | ⚠ Explotación activa | Zyxel ZLD | 27/11/2024 | 5/8/2026 | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an… | |
| Analizada | Alta (7.5) | 0.68% | — | Zyxel P6101c Firmware | 20/11/2024 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device information via a crafted HTTP HEAD method. | |
| Analizada | Media (4.5) | 0.24% | — | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 12/11/2024 | 17/6/2026 | A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL. | |
| Analizada | Media (6.8) | 0.70% | — | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 12/11/2024 | 17/6/2026 | A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted… | |
| Analizada | Alta (7.8) | 0.15% | — | Zyxel UOS | 22/10/2024 | 17/6/2026 | The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+37 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected… | |
| Analizada | Media (4.9) | 0.43% | — | Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+38 | 24/9/2024 | 17/6/2026 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an… | |
| Analizada | Crítica (9.8) | 2.1% | — | Zyxel Nas326 FirmwareZyxel Nas542 Firmware | 10/9/2024 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP… | |
| Analizada | Media (6.5) | 0.21% | — | Zyxel Gs1900-48hpv2 FirmwareZyxel Gs1900-48 FirmwareZyxel Gs1900-24hpv2 FirmwareZyxel Gs1900-24ep Firmware+6 | 10/9/2024 | 17/6/2026 | An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel GS1900-10HP firmware version V2.80(AAZI.0)C0. This vulnerability could allow a LAN-based attacker a slight chance to gain a valid session token if… | |
| Analizada | Crítica (9.8) | 11% | — | Zyxel Nwa110ax FirmwareZyxel Nwa1123-ac PRO FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa130be Firmware+25 | 3/9/2024 | 17/6/2026 | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE… | |
| Analizada | Media (6.1) | 0.31% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware… | |
| Analizada | Alta (7.2) | 1.3% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device by… | |
| Analizada | Media (4.9) | 0.60% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow… | |
| Analizada | Alta (7.5) | 0.66% | — | Zyxel Nebula Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa710 FirmwareZyxel Nebula Fwa510 Firmware+46 | 3/9/2024 | 17/6/2026 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. | |
| Analizada | Alta (7.2) | 1.3% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could… | |
| Analizada | Alta (7.2) | 1.3% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware versions from V5.00 through V5.38 could… | |
| Analizada | Alta (7.5) | 0.62% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from V5.20 through V5.38 could allow an… | |
| Analizada | Alta (8.1) | 1.3% | — | Zyxel ZLD | 3/9/2024 | 17/6/2026 | A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38… | |
| Analizada | Crítica (9.8) | 4.4% | — | Zyxel Nwaw1100-n Firmware | 30/8/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device. | |
| Analizada | Media (6.5) | 0.32% | — | Zyxel Nwa50ax FirmwareZyxel Nwa50ax-pro FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+16 | 23/7/2024 | 17/6/2026 | The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device. | |
| Analizada | Media (6.5) | 9.0% | — | Zyxel Nas326 FirmwareZyxel Nas542 Firmware | 4/6/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session… | |
| Analizada | Media (6.7) | 0.47% | — | Zyxel Nas326 FirmwareZyxel Nas542 Firmware | 4/6/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system… | |
| Analizada | Crítica (9.8) | 23% | — | Zyxel Nas326 FirmwareZyxel Nas542 Firmware | 4/6/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted… |