Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
346 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.32% | — | Zyxel Re210AI | 8/9/2026 | 10/9/2026 | A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to… | |
| Aplazada | Alta (7.3) | 0.25% | — | Zyxel Wah7601AI | 10/8/2026 | 26/8/2026 | Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026. | |
| Aplazada | Media (6.5) | 0.26% | — | Zyxel Networks Wah7601AI | 10/8/2026 | 26/8/2026 | Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Zyxel Wah7601AI | 10/8/2026 | 26/8/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026. | |
| Aplazada | Alta (8.2) | 0.34% | — | Zyxel Networks Wah7601AI | 10/8/2026 | 26/8/2026 | Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. This issue affects WAH7601: through 20072026. | |
| Pendiente de análisis | Alta (7.2) | 0.57% | — | Zyxel ATP Series FirmwareAIZyxel USG Flex Series FirmwareAIZyxel USG Flex 50 Series FirmwareAIZyxel Usg20 VPN Series FirmwareAI | 4/8/2026 | 4/8/2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN… | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Zyxel Wax650sAI | 4/8/2026 | 4/8/2026 | An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication. | |
| Pendiente de análisis | Alta (7.2) | 1.5% | — | Zyxel Wax650sAI | 4/8/2026 | 5/8/2026 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Pendiente de análisis | Alta (7.2) | 1.5% | — | Zyxel Ax7501-b1AI | 21/7/2026 | 23/7/2026 | A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Analizada | Alta (8.8) | 2.5% | ⚠ Explotación activa | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 16/6/2026 | 22/9/2026 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | |
| Aplazada | Media (6.5) | 0.27% | — | Zyxel Vmg4005-b50bAI | 2/6/2026 | 22/7/2026 | A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device. | |
| Aplazada | Media (6.5) | 0.27% | — | Zyxel Vmg4005-b50bAI | 2/6/2026 | 22/7/2026 | A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of-service (DoS) condition affecting the UPnP function of the affected device. | |
| Aplazada | Media (6.5) | 0.30% | — | Zyxel Gs1200-5v3AIZyxel Gs1200-8v3AIZyxel Gs1200-5hpv3AIZyxel Gs1200-8hpv3AI+1 | 26/5/2026 | 24/7/2026 | A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0… | |
| Analizada | Alta (7.5) | 0.55% | — | Zyxel Nwa1100-n Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmware version 1.00(AACE.1)C0 could allow an attacker to trigger a denial-of-service (DoS) condition by… | |
| Analizada | Media (4.4) | 0.15% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file. | |
| Analizada | Alta (8.8) | 2.7% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request. | |
| Analizada | Media (6.5) | 0.32% | — | Zyxel Wre6505 Firmware | 12/5/2026 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication. | |
| Analizada | Alta (7.2) | 1.2% | — | Zyxel Nebula Fwa70 FirmwareZyxel Nebula Fwa505 FirmwareZyxel Nebula Fwa510 FirmwareZyxel Nebula Fwa515 Firmware+41 | 28/4/2026 | 25/7/2026 | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device. | |
| Analizada | Media (6.8) | 0.85% | — | Zyxel Nr5307 FirmwareZyxel Nebula Fwa515 FirmwareZyxel Dx3300-t0 FirmwareZyxel Dx3300-t1 Firmware+32 | 28/4/2026 | 25/7/2026 | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device. | |
| Analizada | Media (5.7) | 0.22% | — | Zyxel Wre6505 Firmware | 21/4/2026 | 8/7/2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator… | |
| Analizada | Alta (7.2) | 0.92% | — | Zyxel Vmg3625-t50c FirmwareZyxel Vmg3625-t50b FirmwareZyxel Emg5523-t50b FirmwareZyxel Emg3525-t50b Firmware+2 | 24/2/2026 | 17/6/2026 | A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device. | |
| Analizada | Alta (8.8) | 1.4% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+48 | 24/2/2026 | 17/6/2026 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | |
| Analizada | Crítica (9.8) | 1.1% | — | Zyxel Wx5610-b0 FirmwareZyxel Lte3301-plus FirmwareZyxel Nebula Lte3301-plus FirmwareZyxel Nr7101 Firmware+14 | 24/2/2026 | 17/6/2026 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests. | |
| Analizada | Media (4.9) | 1.9% | — | Zyxel Ex5601-t1 FirmwareZyxel Ex7501-b0 FirmwareZyxel Ex7710-b0 FirmwareZyxel Gm4100-b0 Firmware+44 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… | |
| Analizada | Media (4.9) | 1.8% | — | Zyxel Ex3510-b1 FirmwareZyxel Ex3600-t0 FirmwareZyxel Ex5401-b1 FirmwareZyxel Ex5510-b0 Firmware+50 | 24/2/2026 | 17/6/2026 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS)… |