Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.4% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+48 | 24/2/2026 | 17/6/2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | |
| Analizada | Crítica (9.8) | 1.1% | — | Zyxel Wx5610-b0 FirmwareZyxel Lte3301-plus FirmwareZyxel Nebula Lte3301-plus FirmwareZyxel Nr7101 Firmware+14 | 24/2/2026 | 17/6/2026 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests. | |
| Analizada | Alta (7.5) | 0.31% | — | Zyxel Lte3301-plus FirmwareZyxel Nr5103 FirmwareZyxel Nr5103e FirmwareZyxel Nr5309 Firmware+62 | 18/11/2025 | 17/6/2026 | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP requests and partially disrupt access to the web… | |
| Analizada | Crítica (9.8) | 0.59% | — | Zyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k FirmwareZyxel Emg6726-b10a Firmware+20 | 16/7/2025 | 17/6/2026 | A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitrary code by sending a specially crafted HTTP request. | |
| Analizada | Alta (7.2) | 1.2% | — | Zyxel Emg6726-b10a FirmwareZyxel Vmg3927-b50b FirmwareZyxel Vmg4005-b50a FirmwareZyxel Vmg4005-b60a Firmware+2 | 3/12/2024 | 17/6/2026 | A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device. | |
| Analizada | Alta (7.5) | 0.52% | — | Zyxel Lte3301-plus FirmwareZyxel Lte5388-m804 FirmwareZyxel Lte5398-m904 FirmwareZyxel Lte7480-m804 Firmware+59 | 3/12/2024 | 17/6/2026 | A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a… | |
| Modificada | Media (5.5) | 0.21% | — | Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+28 | 11/4/2022 | 17/6/2026 | A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service. | |
| Modificada | Alta (8) | 0.70% | — | Zyxel Vmg3312-t20a FirmwareZyxel Emg3525-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg5723-t50k Firmware+28 | 11/4/2022 | 17/6/2026 | A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface. |