Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 14% | 💥 PoC | Zyxel Vmg4325-b10a FirmwareZyxel Sbg3500-n000 FirmwareZyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b Firmware+10 | 4/2/2025 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so. | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa💥 PoC | Zyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+10 | 4/2/2025 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet. | |
| Analizada | Alta (8.8) | 21% | ⚠ Explotación activa | Zyxel Vmg1312-b10a FirmwareZyxel Vmg1312-b10b FirmwareZyxel Vmg1312-b10e FirmwareZyxel Vmg3312-b10a Firmware+10 | 4/2/2025 | 17/6/2026 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST… |