Vulnerabilities

Summary — last 7 days

New vulnerabilities3,241▲ 698 vs. last week
Critical / high1,519▲ 132 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)235▲ 221 vs. last week
–

15 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.8)4.8%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+615/24/20226/17/2026
A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00…
ModifiedHigh (7.8)6.2%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+615/24/20226/17/2026
Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions…
ModifiedMedium (6.5)0.71%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+285/24/20226/17/2026
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through…
ModifiedMedium (6.1)9.4%—Zyxel Vpn100 FirmwareZyxel Vpn1000 FirmwareZyxel Vpn300 FirmwareZyxel Vpn50 Firmware+285/24/20226/17/2026
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to…
ModifiedCritical (9.8)2.3%—Zyxel Usg1900 FirmwareZyxel Usg1100 FirmwareZyxel Usg310 FirmwareZyxel Usg210 Firmware+337/2/20216/17/2026
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
AnalyzedCritical (9.8)90%⚠ Active exploitation💥 ExploitZyxel Usg20-vpn FirmwareZyxel Usg20w-vpn FirmwareZyxel Usg40 FirmwareZyxel Usg40w Firmware+2612/22/20206/17/2026
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
AnalyzedCritical (9.8)100%⚠ Active exploitation💥 ExploitZyxel Nas326 FirmwareZyxel Nas520 FirmwareZyxel Nas540 FirmwareZyxel Nas542 Firmware+233/4/202010/8/2026
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI…
ModifiedMedium (6.1)6.4%💥 ExploitZyxel Uag2100 FirmwareZyxel Uag4100 FirmwareZyxel Uag5100 FirmwareZyxel Usg110 Firmware+56/27/20196/17/2026
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
ModifiedCritical (9.1)44%💥 ExploitZyxel Uag2100 FirmwareZyxel Uag4100 FirmwareZyxel Uag5100 FirmwareZyxel Usg110 Firmware+106/27/20196/17/2026
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
ModifiedMedium (6.1)21%💥 ExploitZyxel Atp200 FirmwareZyxel Atp500 FirmwareZyxel Atp800 FirmwareZyxel Usg20-vpn Firmware+174/22/20196/17/2026
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
ModifiedHigh (8.8)0.40%—Huawei FusionmanagerHuawei Usg9500 FirmwareHuawei Usg2100 FirmwareHuawei Usg2200 Firmware+24/2/20176/17/2026
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of…
ModifiedHigh (8.8)0.40%—Huawei FusionmanagerHuawei Usg9500 FirmwareHuawei Usg2100 FirmwareHuawei Usg2200 Firmware+24/2/20176/17/2026
Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
ModifiedCritical (9.8)5.6%—Huawei Usg2100Huawei Usg2200Huawei Usg5100Huawei Usg550010/3/20166/17/2026
Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600, when CHAP authentication is configured on the server, allows remote attackers to cause a denial of service (server restart) or…
ModifiedHigh (7.5)3.3%—Huawei Usg2100 FirmwareHuawei Usg2200 FirmwareHuawei Usg5100 FirmwareHuawei Usg5500 Firmware9/22/20166/17/2026
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitrary code by sending a crafted EAP packet.
ModifiedMedium (6.5)3.5%💥 ExploitHuawei ACUHuawei AR 19/29/49Huawei AR G3Huawei ATN+626/20/20136/16/2026
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500,…
Orbitaley — Vulnerabilities