Vulnerabilidades en ZyXEL
169 resultadosAnálisis Vexday
ZyXEL apresenta baixo volume de vulnerabilidades catalogadas (3 CVEs), com apenas 1 sob exploração ativa e 1 classificada como crítica, indicando exposição limitada no ecossistema. A fraqueza dominante identificada é autenticação insuficiente (CWE-306), representando o principal vetor de risco. Ausência de publicações recentes nos últimos 90 dias sugere que o risco atual está estabilizado, sem novos problemas emergentes.
CVE-2024-38267MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware verEPSS 0.4%CVE-2024-38266MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware vEPSS 0.4%CVE-2024-38268MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versEPSS 0.4%CVE-2023-28767HIGHThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX serieEPSS 0.4%CVE-2021-35033HIGHA vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password managemEPSS 0.4%CVE-2022-40603MEDIUMA cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firEPSS 0.4%CVE-2026-14818HIGHA path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 throuEPSS 0.4%CVE-2022-45441MEDIUMA cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker tEPSS 0.4%CVE-2022-0556HIGHA local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) EPSS 0.3%CVE-2023-27990MEDIUMThe cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50EPSS 0.3%CVE-2023-33011HIGHA format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 thEPSS 0.3%CVE-2022-34746MEDIUMAn insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was founEPSS 0.3%CVE-2024-1575MEDIUMThe improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an autheEPSS 0.3%CVE-2026-7273HIGHA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow aEPSS 0.3%CVE-2026-7287HIGH** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and foEPSS 0.3%CVE-2025-6599MEDIUMAn uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could EPSS 0.3%CVE-2021-35028HIGHA command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to exEPSS 0.3%CVE-2023-6397MEDIUM
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%CVE-2023-34140MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 EPSS 0.3%CVE-2024-42061MEDIUMA reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.3EPSS 0.3%