Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

346 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Zyxel P1302-t10 V3 Firmware14/12/202017/6/2026
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
ModificadaCrítica (9.8)4.4%—Zyxel ZLDZyxel Access Points Firmware27/11/202017/6/2026
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.
ModificadaCrítica (9.8)2.2%—Zyxel Vmg5313-b30b Firmware2/9/202017/6/2026
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar…
ModificadaAlta (8.8)1.3%—Zyxel Vmg5313-b30b Firmware31/8/202017/6/2026
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
ModificadaAlta (8.8)0.97%—Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware6/8/202017/6/2026
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0,…
ModificadaAlta (8.8)1.2%—Zyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware6/8/202017/6/2026
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and…
ModificadaCrítica (9.8)1.3%—Zyxel Cloud CNM Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.
ModificadaCrítica (9.8)1.3%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
ModificadaCrítica (9.8)1.3%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
ModificadaCrítica (9.8)1.3%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
ModificadaCrítica (9.8)1.3%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
ModificadaMedia (5.9)1.00%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
ModificadaMedia (5.9)1.00%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
ModificadaMedia (5.9)0.98%—Zyxel Cloudcnm Secumanager29/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
ModificadaAlta (7.5)0.93%—Zyxel Cloudcnm Secumanager26/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
ModificadaAlta (7.5)0.93%—Zyxel Cloudcnm Secumanager26/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
ModificadaCrítica (9.8)1.8%—Zyxel Cloud CNM Secumanager26/6/202017/6/2026
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.
ModificadaAlta (8.6)9.5%💥 ExploitZyxel Wap6806 Firmware22/6/202017/6/2026
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
ModificadaAlta (7.5)15%💥 PoCUI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+2138/6/202017/6/2026
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
ModificadaMedia (5.4)0.62%—Zyxel Xgs2210-52hp Firmware31/3/202017/6/2026
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.
Orbitaley — Vulnerabilidades