Перейти к содержимому
Noroxi

Записи Zyxel

331 опубликованных записей вендора zyxel.

Профиль для исследователя

Попали в KEV
13 · 3,9 %
С эксплойтом
20 · 6 %
Pre-auth RCE
42
С записью об исправлении
0,3 %
Медиана: публикация → KEV
12 дн.

Все записи

331 записей
  • CVE-2020-9054
    99Срочно

    ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zyxel · nas326 firmware4 мар. 2020 г.

  • CVE-2022-30525
    99Срочно

    A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    zyxel · usg flex 100w firmware12 мая 2022 г.

  • CVE-2023-28771
    99Срочно

    Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    zyxel · atp100 firmware24 апр. 2023 г.

  • CVE-2017-18368
    97Срочно

    The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %

    zyxel · p660hn-t1a v2 firmware2 мая 2019 г.

  • CVE-2020-29583
    96Срочно

    Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %

    zyxel · usg20-vpn firmware22 дек. 2020 г.

  • CVE-2023-27992
    94Срочно

    The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware vers

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %

    zyxel · nas326 firmware19 июн. 2023 г.

  • CVE-2023-33010
    78На этой неделе

    A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 29 %

    zyxel · atp100 firmware24 мая 2023 г.

  • CVE-2023-33009
    77На этой неделе

    A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 28 %

    zyxel · atp100 firmware24 мая 2023 г.

  • CVE-2017-6884
    75На этой неделе

    A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8.

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 35 %

    zyxel · emg2926 firmware6 апр. 2017 г.

  • CVE-2024-40891
    71На этой неделе

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel V

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 22 %

    zyxel · vmg1312-b10a firmware4 февр. 2025 г.

  • CVE-2024-40890
    71На этой неделе

    **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 21 %

    zyxel · vmg1312-b10a firmware4 февр. 2025 г.

  • CVE-2024-11667
    70На этой неделе

    A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX seri

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %

    zyxel · zld27 нояб. 2024 г.

  • CVE-2022-0342
    68На этой неделе

    An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series fi

    КритическаяCVSS 9,8Proof of conceptEPSS 95 %

    zyxel · usg40 firmware28 мар. 2022 г.

  • CVE-2024-29972
    66На этой неделе

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions b

    КритическаяCVSS 9,8Proof of conceptEPSS 89 %

    zyxel · nas326 firmware3 июн. 2024 г.

  • CVE-2026-7273
    66На этой неделе

    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %

    zyxel · gs1900-8 firmware15 июн. 2026 г.

  • CVE-2024-29973
    65На этой неделе

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5

    КритическаяCVSS 9,8Proof of conceptEPSS 86 %

    zyxel · nas326 firmware3 июн. 2024 г.

  • CVE-2021-4039
    60На этой неделе

    A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS com

    КритическаяCVSS 9,8Proof of conceptEPSS 71 %

    zyxel · nwa1100-nh firmware1 мар. 2022 г.

  • CVE-2023-37928
    53В плане

    A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 60 %

    zyxel · nas326 firmware29 нояб. 2023 г.

  • CVE-2023-4473
    51В плане

    A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(

    КритическаяCVSS 9,8Эксплойта нетEPSS 41 %

    zyxel · nas326 firmware29 нояб. 2023 г.

  • CVE-2023-35138
    51В плане

    A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NA

    КритическаяCVSS 9,8Эксплойта нетEPSS 40 %

    zyxel · nas326 firmware29 нояб. 2023 г.

  • CVE-2019-12583
    49В плане

    Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest

    КритическаяCVSS 9,1Proof of conceptEPSS 44 %

    zyxel · uag2100 firmware27 июн. 2019 г.

  • CVE-2023-4474
    48В плане

    The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware

    КритическаяCVSS 9,8Эксплойта нетEPSS 30 %

    zyxel · nas326 firmware29 нояб. 2023 г.

  • CVE-2023-28770
    47В плане

    The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 58 %

    zyxel · dx5401-b0 firmware27 апр. 2023 г.

  • CVE-2024-29974
    46В плане

    ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versio

    КритическаяCVSS 9,8Эксплойта нетEPSS 23 %

    zyxel · nas326 firmware3 июн. 2024 г.

  • CVE-2017-18371
    46В плане

    The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two

    КритическаяCVSS 9,8Готовый эксплойтEPSS 23 %

    zyxel · p660hn-t1a v2 firmware2 мая 2019 г.