Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.2%—Zyxel P-660h-61Zyxel P-660h-63Zyxel P-660h-67Zyxel P-660h-d1+72/4/201416/6/2026
The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.
ModificadaAlta (7.5)0.89%—Zyxel P-663hn-51 FirmwareZyxel P-660h-61 FirmwareZyxel P-660h-63 FirmwareZyxel P-660h-67 Firmware+1526/3/200816/6/2026
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
ModificadaMedia (4.3)1.6%—Zyxel P-660hwZyxel P-660hw D1Zyxel P-660hw D3Zyxel P-660hw T310/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.