Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.71%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+2824/5/202217/6/2026
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through…
ModificadaMedia (6.1)9.4%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+2824/5/202217/6/2026
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZyxel USG Flex 100w FirmwareZyxel USG Flex 200 FirmwareZyxel USG Flex 500 FirmwareZyxel USG Flex 700 Firmware+1212/5/202217/6/2026
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W)…
ModificadaMedia (5.5)0.21%—Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+2811/4/202217/6/2026
A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service.
ModificadaAlta (8)0.70%—Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+2811/4/202217/6/2026
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
ModificadaAlta (7.8)0.37%—Zyxel AP Configurator11/4/202217/6/2026
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
ModificadaCrítica (9.8)95%💥 ExploitZyxel Usg40 FirmwareZyxel Usg40w FirmwareZyxel Usg60 FirmwareZyxel Usg60w Firmware+1928/3/202217/6/2026
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through…
ModificadaMedia (6.1)21%💥 ExploitZyxel Zywall 2 Plus Internet Security Appliance Firmware1/3/202217/6/2026
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session…
ModificadaCrítica (9.8)71%💥 ExploitZyxel Nwa1100-nh Firmware1/3/202217/6/2026
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
ModificadaMedia (6.5)0.49%💥 PoCZyxel Ax7501-b0 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx5401-b0 FirmwareZyxel Emg3525-t50b Firmware+271/3/202217/6/2026
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
ModificadaAlta (8.8)0.44%—Zyxel Nbg6816 FirmwareZyxel Nbg6817 Firmware24/2/202217/6/2026
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.
ModificadaAlta (8.8)0.75%—Zyxel Nbg6816 FirmwareZyxel Nbg6817 Firmware24/2/202217/6/2026
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.
ModificadaMedia (6.5)0.65%—Zyxel Nbg6604 Firmware29/12/202117/6/2026
A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
ModificadaCrítica (9.1)1.0%—Zyxel Nbg6604 Firmware29/12/202117/6/2026
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
ModificadaAlta (7.8)0.21%—Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+828/12/202117/6/2026
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
ModificadaAlta (8)0.46%—Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+1028/12/202117/6/2026
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
ModificadaAlta (7.8)0.41%—Zyxel Nbg6818 FirmwareZyxel Nbg7815 FirmwareZyxel Wsq20 FirmwareZyxel Wsq50 Firmware+223/11/202117/6/2026
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote…
ModificadaAlta (7.8)0.30%—Zyxel Zywall Vpn2s Firmware29/9/202117/6/2026
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
ModificadaAlta (7.5)2.0%—Zyxel Zywall Vpn2s Firmware29/9/202117/6/2026
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
ModificadaMedia (4.3)0.27%—Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+826/7/202117/6/2026
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.
ModificadaCrítica (9.8)2.3%—Zyxel Usg1900 FirmwareZyxel Usg1100 FirmwareZyxel Usg310 FirmwareZyxel Usg210 Firmware+332/7/202117/6/2026
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
ModificadaCrítica (9.1)1.7%—Zyxel Lte4506-m606 FirmwareZyxel Lte7460-m608 FirmwareZyxel Wah7706 Firmware16/3/202117/6/2026
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS…
ModificadaAlta (7.8)21%💥 ExploitZyxel Nbg2105 Firmware26/1/202117/6/2026
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
ModificadaAlta (7.2)2.4%—Zyxel VPN OrchestratorZyxel ZLDZyxel NSG FirmwareZyxel USG Flex Firmware27/12/202017/6/2026
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38,…
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitZyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+2622/12/202017/6/2026
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
Orbitaley — Vulnerabilidades