Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
346 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+15 | 24/4/2023 | 17/6/2026 | The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions… | |
| Modificada | Media (4.8) | 0.34% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+15 | 24/4/2023 | 17/6/2026 | The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which… | |
| Modificada | Media (6.5) | 0.77% | — | Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+47 | 24/4/2023 | 17/6/2026 | A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions… | |
| Modificada | Alta (7.5) | 0.88% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+14 | 24/4/2023 | 17/6/2026 | A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00… | |
| Modificada | Alta (8.1) | 0.69% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+14 | 24/4/2023 | 17/6/2026 | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly… | |
| Modificada | Alta (7.5) | 1.1% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+8 | 24/4/2023 | 17/6/2026 | A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote… | |
| Modificada | Alta (7.2) | 1.0% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+7 | 24/4/2023 | 17/6/2026 | A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp”… | |
| Modificada | Alta (8.1) | 1.3% | — | Zyxel USG Flex 100 FirmwareZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 50 Firmware+7 | 24/4/2023 | 17/6/2026 | A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker to modify device configuration data, resulting in… | |
| Modificada | Crítica (9.8) | 0.84% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3316-m604 Firmware | 21/2/2023 | 17/6/2026 | A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet. | |
| Modificada | Media (4.3) | 0.28% | — | Zyxel Nwa110ax FirmwareZyxel Nwa210ax FirmwareZyxel Wax510d FirmwareZyxel Wax610d Firmware+2 | 7/2/2023 | 17/6/2026 | An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were intercepted by the attacker. | |
| Modificada | Media (6.1) | 0.35% | — | Zyxel Nbg-418n Firmware | 7/2/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and… | |
| Modificada | Alta (7.2) | 2.8% | — | Zyxel Atp100 FirmwareZyxel Atp200 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+21 | 7/2/2023 | 17/6/2026 | A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series firmware versions 4.30 through 5.32, USG FLEX series firmware versions 4.50 through 5.32, and ATP series firmware versions 4.32 through 5.32, which could allow an… | |
| Modificada | Media (4.4) | 0.25% | — | Zyxel Ax7501-b0 Firmware | 17/1/2023 | 17/6/2026 | A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability to access the root file system by creating a symbolic link on external… | |
| Modificada | Media (6.5) | 0.20% | — | Zyxel Ax7501-b0 Firmware | 17/1/2023 | 17/6/2026 | A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the device by leveraging another known… | |
| Modificada | Alta (8.2) | 0.56% | — | Zyxel Gs1350-6hp FirmwareZyxel Gs1350-12hp FirmwareZyxel Gs1350-18hp FirmwareZyxel Gs1350-26hp Firmware+41 | 11/1/2023 | 17/6/2026 | An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device. | |
| Modificada | Media (6.5) | 0.62% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. | |
| Modificada | Media (6.5) | 0.72% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7240-m403 Firmware+44 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request. | |
| Modificada | Alta (8.8) | 1.1% | — | Zyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 FirmwareZyxel Nebula Nr5101 FirmwareZyxel Nebula Nr7101 Firmware+35 | 11/1/2023 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 0.61% | — | Zyxel Lte3202-m437 FirmwareZyxel Lte3316-m604 FirmwareZyxel Lte7480-m804 FirmwareZyxel Lte7490-m904 Firmware+13 | 11/1/2023 | 17/6/2026 | A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device. | |
| Modificada | Crítica (9.8) | 0.64% | — | Zyxel Nbg7510 Firmware | 21/12/2022 | 17/6/2026 | A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode. | |
| Modificada | Media (6.1) | 0.39% | — | Zyxel Atp800 FirmwareZyxel Atp700 FirmwareZyxel Atp500 FirmwareZyxel Atp200 Firmware+15 | 6/12/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a… | |
| Modificada | Crítica (9.8) | 1.1% | — | Zyxel Lte3301-m209 Firmware | 22/11/2022 | 17/6/2026 | A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator. | |
| Modificada | Crítica (9.8) | 1.3% | — | Zyxel Cloudcnm Secumanager | 29/9/2022 | 17/6/2026 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. | |
| Modificada | Media (5.3) | 0.57% | — | Zyxel Cloudcnm Secumanager | 29/9/2022 | 17/6/2026 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key. | |
| Modificada | Media (5.3) | 0.57% | — | Zyxel Cloudcnm Secumanager | 29/9/2022 | 17/6/2026 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API. |