Записи Zyxel
331 опубликованных записей вендора zyxel.
Профиль для исследователя
- Попали в KEV
- 13 · 3,9 %
- С эксплойтом
- 20 · 6 %
- Pre-auth RCE
- 42
- С записью об исправлении
- 0,3 %
- Медиана: публикация → KEV
- 12 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')61
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')25
- CWE-798 Use of Hard-coded Credentials22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-269 Improper Privilege Management14
- CWE-287 Improper Authentication14
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
331 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2020-9054Готовый эксплойт | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 4 мар. 2020 г. |
99Срочно | CVE-2022-30525Готовый эксплойт | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 12 мая 2022 г. |
99Срочно | CVE-2023-28771Готовый эксплойт | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Критическая9,8 | KEV | 99,3 % | 24 апр. 2023 г. |
97Срочно | CVE-2017-18368Готовый эксплойт | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability inzyxel · p660hn-t1a v2 firmware · CWE-78 | Критическая9,8 | KEV | 94,4 % | 2 мая 2019 г. |
96Срочно | CVE-2020-29583Готовый эксплойт | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.zyxel · usg20-vpn firmware · CWE-522 | Критическая9,8 | KEV | 90,2 % | 22 дек. 2020 г. |
94Срочно | CVE-2023-27992Готовый эксплойт | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware verszyxel · nas326 firmware · CWE-78 | Критическая9,8 | KEV | 82,8 % | 19 июн. 2023 г. |
78На этой неделе | CVE-2023-33010Готовый эксплойт | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX serizyxel · atp100 firmware · CWE-120 | Критическая9,8 | KEV | 28,8 % | 24 мая 2023 г. |
77На этой неделе | CVE-2023-33009Готовый эксплойт | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX seriezyxel · atp100 firmware · CWE-120 | Критическая9,8 | KEV | 28,1 % | 24 мая 2023 г. |
75На этой неделе | CVE-2017-6884Готовый эксплойт | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8.zyxel · emg2926 firmware · CWE-78 | Высокая8,8 | KEV | 34,6 % | 6 апр. 2017 г. |
71На этой неделе | CVE-2024-40891Готовый эксплойт | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel Vzyxel · vmg1312-b10a firmware · CWE-78 | Высокая8,8 | KEV | 21,5 % | 4 февр. 2025 г. |
71На этой неделе | CVE-2024-40890Готовый эксплойт | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-Bzyxel · vmg1312-b10a firmware · CWE-78 | Высокая8,8 | KEV | 20,7 % | 4 февр. 2025 г. |
70На этой неделе | CVE-2024-11667Готовый эксплойт | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX serizyxel · zld · CWE-22 | Критическая9,8 | KEV | 2,9 % | 27 нояб. 2024 г. |
68На этой неделе | CVE-2022-0342Proof of concept | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series fizyxel · usg40 firmware · CWE-287 | Критическая9,8 | — | 95,1 % | 28 мар. 2022 г. |
66На этой неделе | CVE-2024-29972Proof of concept | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions bzyxel · nas326 firmware · CWE-78 | Критическая9,8 | — | 89,3 % | 3 июн. 2024 г. |
66На этой неделе | CVE-2026-7273Готовый эксплойт | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow azyxel · gs1900-8 firmware · CWE-121 | Высокая8,8 | KEV | 2,5 % | 15 июн. 2026 г. |
65На этой неделе | CVE-2024-29973Proof of concept | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5zyxel · nas326 firmware · CWE-78 | Критическая9,8 | — | 86,1 % | 3 июн. 2024 г. |
60На этой неделе | CVE-2021-4039Proof of concept | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS comzyxel · nwa1100-nh firmware · CWE-78 | Критическая9,8 | — | 71,0 % | 1 мар. 2022 г. |
53В плане | CVE-2023-37928Эксплойта нет | A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fizyxel · nas326 firmware · CWE-78 | Высокая8,8 | — | 60,2 % | 29 нояб. 2023 г. |
51В плане | CVE-2023-4473Эксплойта нет | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(zyxel · nas326 firmware · CWE-78 | Критическая9,8 | — | 41,3 % | 29 нояб. 2023 г. |
51В плане | CVE-2023-35138Эксплойта нет | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAzyxel · nas326 firmware · CWE-78 | Критическая9,8 | — | 40,0 % | 29 нояб. 2023 г. |
49В плане | CVE-2019-12583Proof of concept | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestzyxel · uag2100 firmware · CWE-425 | Критическая9,1 | — | 43,9 % | 27 июн. 2019 г. |
48В плане | CVE-2023-4474Эксплойта нет | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwarezyxel · nas326 firmware · CWE-78 | Критическая9,8 | — | 29,7 % | 29 нояб. 2023 г. |
47В плане | CVE-2023-28770Готовый эксплойт | The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior tozyxel · dx5401-b0 firmware · CWE-200 | Высокая7,5 | — | 57,8 % | 27 апр. 2023 г. |
46В плане | CVE-2024-29974Эксплойта нет | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versiozyxel · nas326 firmware · CWE-434 | Критическая9,8 | — | 22,8 % | 3 июн. 2024 г. |
46В плане | CVE-2017-18371Готовый эксплойт | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two zyxel · p660hn-t1a v2 firmware · CWE-798 | Критическая9,8 | — | 22,5 % | 2 мая 2019 г. |
- CVE-2020-905499Срочно
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · nas326 firmware4 мар. 2020 г.
- CVE-2022-3052599Срочно
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · usg flex 100w firmware12 мая 2022 г.
- CVE-2023-2877199Срочно
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %zyxel · atp100 firmware24 апр. 2023 г.
- CVE-2017-1836897Срочно
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %zyxel · p660hn-t1a v2 firmware2 мая 2019 г.
- CVE-2020-2958396Срочно
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %zyxel · usg20-vpn firmware22 дек. 2020 г.
- CVE-2023-2799294Срочно
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware vers
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %zyxel · nas326 firmware19 июн. 2023 г.
- CVE-2023-3301078На этой неделе
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 29 %zyxel · atp100 firmware24 мая 2023 г.
- CVE-2023-3300977На этой неделе
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 28 %zyxel · atp100 firmware24 мая 2023 г.
- CVE-2017-688475На этой неделе
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 35 %zyxel · emg2926 firmware6 апр. 2017 г.
- CVE-2024-4089171На этой неделе
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel V
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 22 %zyxel · vmg1312-b10a firmware4 февр. 2025 г.
- CVE-2024-4089071На этой неделе
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 21 %zyxel · vmg1312-b10a firmware4 февр. 2025 г.
- CVE-2024-1166770На этой неделе
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX seri
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %zyxel · zld27 нояб. 2024 г.
- CVE-2022-034268На этой неделе
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series fi
КритическаяCVSS 9,8Proof of conceptEPSS 95 %zyxel · usg40 firmware28 мар. 2022 г.
- CVE-2024-2997266На этой неделе
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions b
КритическаяCVSS 9,8Proof of conceptEPSS 89 %zyxel · nas326 firmware3 июн. 2024 г.
- CVE-2026-727366На этой неделе
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %zyxel · gs1900-8 firmware15 июн. 2026 г.
- CVE-2024-2997365На этой неделе
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5
КритическаяCVSS 9,8Proof of conceptEPSS 86 %zyxel · nas326 firmware3 июн. 2024 г.
- CVE-2021-403960На этой неделе
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS com
КритическаяCVSS 9,8Proof of conceptEPSS 71 %zyxel · nwa1100-nh firmware1 мар. 2022 г.
- CVE-2023-3792853В плане
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fi
ВысокаяCVSS 8,8Эксплойта нетEPSS 60 %zyxel · nas326 firmware29 нояб. 2023 г.
- CVE-2023-447351В плане
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(
КритическаяCVSS 9,8Эксплойта нетEPSS 41 %zyxel · nas326 firmware29 нояб. 2023 г.
- CVE-2023-3513851В плане
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NA
КритическаяCVSS 9,8Эксплойта нетEPSS 40 %zyxel · nas326 firmware29 нояб. 2023 г.
- CVE-2019-1258349В плане
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest
КритическаяCVSS 9,1Proof of conceptEPSS 44 %zyxel · uag2100 firmware27 июн. 2019 г.
- CVE-2023-447448В плане
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware
КритическаяCVSS 9,8Эксплойта нетEPSS 30 %zyxel · nas326 firmware29 нояб. 2023 г.
- CVE-2023-2877047В плане
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to
ВысокаяCVSS 7,5Готовый эксплойтEPSS 58 %zyxel · dx5401-b0 firmware27 апр. 2023 г.
- CVE-2024-2997446В плане
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versio
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %zyxel · nas326 firmware3 июн. 2024 г.
- CVE-2017-1837146В плане
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two
КритическаяCVSS 9,8Готовый эксплойтEPSS 23 %zyxel · p660hn-t1a v2 firmware2 мая 2019 г.