Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.17%—Zyxel Gs1900-48hpv2 FirmwareZyxel Gs1900-48 FirmwareZyxel Gs1900-24hpv2 FirmwareZyxel Gs1900-24ep Firmware+67/11/202317/6/2026
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
ModificadaAlta (7.5)0.79%—Zyxel Pmg2005-t20b Firmware27/9/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauthenticated attacker to cause a denial of service condition via a crafted uid.
ModificadaAlta (8.8)1.7%—Zyxel Nbg6604 Firmware14/8/202317/6/2026
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
ModificadaMedia (6.5)0.30%—Zyxel Xgs2220-30 FirmwareZyxel Xgs2220-30f FirmwareZyxel Xgs2220-30hp FirmwareZyxel Xgs2220-54 Firmware+714/8/202317/6/2026
Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1), and XS1930-10 firmware version V4.80(ABQE.1) could allow an unauthenticated LAN-based attacker to cause denial-of-service (DoS) conditions by sending crafted frames to an affected switch.
ModificadaAlta (8)0.68%—Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+2017/7/202317/6/2026
A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.00 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.00…
ModificadaMedia (6.5)0.30%—Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+2017/7/202317/6/2026
A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware…
ModificadaAlta (8.8)0.76%—Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+1117/7/202317/6/2026
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands on an affected device.
ModificadaAlta (8)0.68%—Zyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+1817/7/202317/6/2026
A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.60 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.60 through…
ModificadaAlta (8.8)9.9%💥 ExploitZyxel USG 20w-vpn FirmwareZyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w Firmware+1817/7/202317/6/2026
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36…
ModificadaAlta (8.8)0.34%—Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+1817/7/202317/6/2026
A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware…
ModificadaAlta (8.8)0.40%—Zyxel USG 2200-vpn FirmwareZyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 Firmware+1817/7/202317/6/2026
The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36, USG FLEX 50(W) series firmware versions 5.10 through 5.36, USG20(W)-VPN series firmware versions 5.10 through 5.36, and VPN series firmware…
AnalizadaCrítica (9.8)83%⚠ Explotación activaZyxel Nas326 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware19/6/202317/6/2026
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands…
ModificadaMedia (6.5)1.0%—Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nr7101 FirmwareZyxel Nebula Nr7101 Firmware5/6/202317/6/2026
A buffer overflow vulnerability in the CGI program of the Zyxel NR7101 firmware versions prior to V1.00(ABUV.8)C0 could allow a remote authenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
ModificadaMedia (6.7)0.17%—Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+630/5/202317/6/2026
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable device via SSH.
ModificadaAlta (7.2)1.4%—Zyxel Nas326 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware30/5/202317/6/2026
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device remotely.
AnalizadaCrítica (9.8)29%⚠ Explotación activaZyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+1924/5/202317/6/2026
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series…
AnalizadaCrítica (9.8)28%⚠ Explotación activaZyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp100w Firmware+1924/5/202317/6/2026
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series…
ModificadaMedia (4.9)0.80%—Zyxel Nbg-418n Firmware1/5/202317/6/2026
A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device.
ModificadaMedia (6.5)0.79%—Zyxel Nbg-418n Firmware1/5/202317/6/2026
A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker to cause denial-of-service (DoS) conditions on an affected device.
ModificadaAlta (7.5)0.93%—Zyxel Nbg-418n Firmware1/5/202317/6/2026
A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device.
ModificadaAlta (7.5)0.50%—Zyxel Nbg-418n Firmware1/5/202317/6/2026
A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected…
ModificadaAlta (8.8)1.6%—Zyxel Nbg6604 Firmware1/5/202317/6/2026
The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
ModificadaAlta (7.5)58%💥 ExploitZyxel Dx5401-b0 Firmware27/4/202317/6/2026
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.
ModificadaCrítica (9.8)5.4%💥 ExploitZyxel Dx5401-b0 Firmware27/4/202317/6/2026
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitZyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+1525/4/202317/6/2026
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS…