Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.4%—Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+4824/2/202617/6/2026
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
AnalizadaCrítica (9.8)1.1%—Zyxel Wx5610-b0 FirmwareZyxel Lte3301-plus FirmwareZyxel Nebula Lte3301-plus FirmwareZyxel Nr7101 Firmware+1424/2/202617/6/2026
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.
AnalizadaMedia (4.9)1.9%—Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+4424/2/202617/6/2026
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)1.8%—Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)1.2%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)…
AnalizadaMedia (4.9)0.81%—Zyxel Lte3301-plus FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+5024/2/202617/6/2026
A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service…
AnalizadaAlta (8.8)1.1%—Zyxel Dm4200-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+5018/11/202517/6/2026
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
AnalizadaAlta (7.2)1.1%—Zyxel Wx5610-b0 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 Firmware+3711/3/202517/6/2026
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaAlta (7.2)1.1%—Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+3411/3/202517/6/2026
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
AnalizadaMedia (4.9)0.51%—Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+323/12/202417/6/2026
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management…
AnalizadaAlta (7.5)0.52%—Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7480-m804 Firmware+593/12/202417/6/2026
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a…
AnalizadaMedia (4.9)0.43%—Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+3724/9/202417/6/2026
An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an…
AnalizadaMedia (4.9)0.43%—Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+3724/9/202417/6/2026
An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected…
AnalizadaMedia (4.9)0.43%—Zyxel Wx5600-t0 FirmwareZyxel Wx3401-b0 FirmwareZyxel Wx3100-t0 FirmwareZyxel Scr50axe Firmware+3724/9/202417/6/2026
An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an affected…
AnalizadaMedia (4.9)0.43%—Zyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 FirmwareZyxel Dx3301-t0 FirmwareZyxel Dx4510-b0 Firmware+3824/9/202417/6/2026
An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions, resulting in a thread crash on an…
Orbitaley — Vulnerabilidades