Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Zyxel P-660hw V3 Firmware | 16/1/2018 | 17/6/2026 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets. | |
| Modificada | Alta (7.5) | 2.3% | — | Zyxel P-660hw Firmware | 29/12/2017 | 17/6/2026 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1. | |
| Modificada | Media (6.1) | 2.1% | — | Zyxel P-660hw-t1 V2 Firmware | 31/12/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter. | |
| Modificada | Media (6.8) | 2.6% | — | Zyxel P-660hw | 16/6/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1. | |
| Modificada | Alta (7.8) | 2.2% | — | Zyxel P-660h-61Zyxel P-660h-63Zyxel P-660h-67Zyxel P-660h-d1+7 | 2/4/2014 | 16/6/2026 | The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets. | |
| Modificada | Media (4.3) | 2.2% | — | Allegrosoft RompagerDlink Dsl-2640rDlink Dsl-2641rHuawei Mt882+3 | 16/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or… | |
| Modificada | Alta (7.5) | 0.89% | — | Zyxel P-663hn-51 FirmwareZyxel P-660h-61 FirmwareZyxel P-660h-63 FirmwareZyxel P-660h-67 Firmware+15 | 26/3/2008 | 16/6/2026 | ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords. | |
| Modificada | Alta (10) | 3.9% | — | Zyxel P-660hw | 10/3/2008 | 16/6/2026 | The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user. | |
| Modificada | Media (4.3) | 1.6% | — | Zyxel P-660hwZyxel P-660hw D1Zyxel P-660hw D3Zyxel P-660hw T3 | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter. | |
| Modificada | Alta (10) | 3.3% | — | Zyxel P-660hw | 10/3/2008 | 16/6/2026 | The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access. | |
| Modificada | Media (6.8) | 0.99% | — | Zyxel P-660hw | 10/3/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors. |