Vulnerabilidades em ZyXEL

169 resultados
Análise Vexday

ZyXEL apresenta baixo volume de vulnerabilidades catalogadas (3 CVEs), com apenas 1 sob exploração ativa e 1 classificada como crítica, indicando exposição limitada no ecossistema. A fraqueza dominante identificada é autenticação insuficiente (CWE-306), representando o principal vetor de risco. Ausência de publicações recentes nos últimos 90 dias sugere que o risco atual está estabilizado, sem novos problemas emergentes.

CVE-2024-42058HIGHA null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions fEPSS 0.6%CVE-2022-43392MEDIUMA buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an autheEPSS 0.6%CVE-2022-38546MEDIUMA DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker EPSS 0.6%CVE-2022-43389HIGHA buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unaEPSS 0.6%CVE-2024-6343MEDIUMA buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware EPSS 0.6%CVE-2022-43393HIGHAn improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70EPSS 0.6%CVE-2023-37929MEDIUMThe buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remotEPSS 0.5%CVE-2025-7673CRITICALA buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 EPSS 0.5%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.5%CVE-2024-12398HIGHAn improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) anEPSS 0.5%CVE-2025-6265HIGHA path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allowEPSS 0.5%CVE-2023-22921HIGHA cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authentEPSS 0.5%CVE-2024-8748HIGHA buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through EPSS 0.5%CVE-2021-35036MEDIUMA cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated atEPSS 0.5%CVE-2024-9197MEDIUMA post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions thrEPSS 0.5%CVE-2024-29975MEDIUM** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versiEPSS 0.5%CVE-2021-35031MEDIUMA vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow EPSS 0.5%CVE-2023-35139MEDIUMA cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.37, USG FLEX series fEPSS 0.5%CVE-2021-4030HIGHA cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitraryEPSS 0.4%CVE-2024-38269MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmwarEPSS 0.4%