Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Zyxel P-660hw V3 Firmware16/1/201817/6/2026
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.
ModificadaAlta (7.5)2.3%—Zyxel P-660hw Firmware29/12/201717/6/2026
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
ModificadaMedia (6.1)2.1%—Zyxel P-660hw-t1 V2 Firmware31/12/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
ModificadaMedia (6.8)2.6%—Zyxel P-660hw16/6/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.
ModificadaAlta (7.8)2.2%—Zyxel P-660h-61Zyxel P-660h-63Zyxel P-660h-67Zyxel P-660h-d1+72/4/201416/6/2026
The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.
ModificadaMedia (4.3)2.2%—Allegrosoft RompagerDlink Dsl-2640rDlink Dsl-2641rHuawei Mt882+316/1/201417/6/2026
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or…
ModificadaAlta (7.5)0.89%—Zyxel P-663hn-51 FirmwareZyxel P-660h-61 FirmwareZyxel P-660h-63 FirmwareZyxel P-660h-67 Firmware+1526/3/200816/6/2026
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
ModificadaAlta (10)3.9%—Zyxel P-660hw10/3/200816/6/2026
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
ModificadaMedia (4.3)1.6%—Zyxel P-660hwZyxel P-660hw D1Zyxel P-660hw D3Zyxel P-660hw T310/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
ModificadaAlta (10)3.3%—Zyxel P-660hw10/3/200816/6/2026
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
ModificadaMedia (6.8)0.99%—Zyxel P-660hw10/3/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.