zyxel kayıtları
zyxel üreticisine ait 331 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 13 · %3,9
- Silahlaştırılmış
- 20 · %6
- Pre-auth RCE
- 42
- Düzeltme kaydı olan
- %0,3
- Yayından KEV’e ortanca
- 12 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')61
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')25
- CWE-798 Use of Hard-coded Credentials22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-269 Improper Privilege Management14
- CWE-287 Improper Authentication14
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
331 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2020-9054Silahlaştırılmış | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Kritik9,8 | KEV | %100,0 | 4 Mar 2020 |
99Hemen | CVE-2022-30525Silahlaştırılmış | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Kritik9,8 | KEV | %99,9 | 12 May 2022 |
99Hemen | CVE-2023-28771Silahlaştırılmış | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Kritik9,8 | KEV | %99,3 | 24 Nis 2023 |
97Hemen | CVE-2017-18368Silahlaştırılmış | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability inzyxel · p660hn-t1a v2 firmware · CWE-78 | Kritik9,8 | KEV | %94,4 | 2 May 2019 |
96Hemen | CVE-2020-29583Silahlaştırılmış | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.zyxel · usg20-vpn firmware · CWE-522 | Kritik9,8 | KEV | %90,2 | 22 Ara 2020 |
94Hemen | CVE-2023-27992Silahlaştırılmış | The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware verszyxel · nas326 firmware · CWE-78 | Kritik9,8 | KEV | %82,8 | 19 Haz 2023 |
78Bu hafta | CVE-2023-33010Silahlaştırılmış | A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX serizyxel · atp100 firmware · CWE-120 | Kritik9,8 | KEV | %28,8 | 24 May 2023 |
77Bu hafta | CVE-2023-33009Silahlaştırılmış | A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX seriezyxel · atp100 firmware · CWE-120 | Kritik9,8 | KEV | %28,1 | 24 May 2023 |
75Bu hafta | CVE-2017-6884Silahlaştırılmış | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8.zyxel · emg2926 firmware · CWE-78 | Yüksek8,8 | KEV | %34,6 | 6 Nis 2017 |
71Bu hafta | CVE-2024-40891Silahlaştırılmış | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel Vzyxel · vmg1312-b10a firmware · CWE-78 | Yüksek8,8 | KEV | %21,5 | 4 Şub 2025 |
71Bu hafta | CVE-2024-40890Silahlaştırılmış | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-Bzyxel · vmg1312-b10a firmware · CWE-78 | Yüksek8,8 | KEV | %20,7 | 4 Şub 2025 |
70Bu hafta | CVE-2024-11667Silahlaştırılmış | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX serizyxel · zld · CWE-22 | Kritik9,8 | KEV | %2,9 | 27 Kas 2024 |
68Bu hafta | CVE-2022-0342Kavram kanıtı | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series fizyxel · usg40 firmware · CWE-287 | Kritik9,8 | — | %95,1 | 28 Mar 2022 |
66Bu hafta | CVE-2024-29972Kavram kanıtı | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions bzyxel · nas326 firmware · CWE-78 | Kritik9,8 | — | %89,3 | 3 Haz 2024 |
66Bu hafta | CVE-2026-7273Silahlaştırılmış | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow azyxel · gs1900-8 firmware · CWE-121 | Yüksek8,8 | KEV | %2,5 | 15 Haz 2026 |
65Bu hafta | CVE-2024-29973Kavram kanıtı | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5zyxel · nas326 firmware · CWE-78 | Kritik9,8 | — | %86,1 | 3 Haz 2024 |
60Bu hafta | CVE-2021-4039Kavram kanıtı | A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS comzyxel · nwa1100-nh firmware · CWE-78 | Kritik9,8 | — | %71,0 | 1 Mar 2022 |
53Planlayın | CVE-2023-37928İstismar yok | A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fizyxel · nas326 firmware · CWE-78 | Yüksek8,8 | — | %60,2 | 29 Kas 2023 |
51Planlayın | CVE-2023-4473İstismar yok | A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(zyxel · nas326 firmware · CWE-78 | Kritik9,8 | — | %41,3 | 29 Kas 2023 |
51Planlayın | CVE-2023-35138İstismar yok | A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAzyxel · nas326 firmware · CWE-78 | Kritik9,8 | — | %40,0 | 29 Kas 2023 |
49Planlayın | CVE-2019-12583Kavram kanıtı | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestzyxel · uag2100 firmware · CWE-425 | Kritik9,1 | — | %43,9 | 27 Haz 2019 |
48Planlayın | CVE-2023-4474İstismar yok | The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwarezyxel · nas326 firmware · CWE-78 | Kritik9,8 | — | %29,7 | 29 Kas 2023 |
47Planlayın | CVE-2023-28770Silahlaştırılmış | The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior tozyxel · dx5401-b0 firmware · CWE-200 | Yüksek7,5 | — | %57,8 | 27 Nis 2023 |
46Planlayın | CVE-2024-29974İstismar yok | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versiozyxel · nas326 firmware · CWE-434 | Kritik9,8 | — | %22,8 | 3 Haz 2024 |
46Planlayın | CVE-2017-18371Silahlaştırılmış | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two zyxel · p660hn-t1a v2 firmware · CWE-798 | Kritik9,8 | — | %22,5 | 2 May 2019 |
- CVE-2020-905499Hemen
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100zyxel · nas326 firmware4 Mar 2020
- CVE-2022-3052599Hemen
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100zyxel · usg flex 100w firmware12 May 2022
- CVE-2023-2877199Hemen
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99zyxel · atp100 firmware24 Nis 2023
- CVE-2017-1836897Hemen
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94zyxel · p660hn-t1a v2 firmware2 May 2019
- CVE-2020-2958396Hemen
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90zyxel · usg20-vpn firmware22 Ara 2020
- CVE-2023-2799294Hemen
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware vers
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83zyxel · nas326 firmware19 Haz 2023
- CVE-2023-3301078Bu hafta
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX seri
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %29zyxel · atp100 firmware24 May 2023
- CVE-2023-3300977Bu hafta
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX serie
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %28zyxel · atp100 firmware24 May 2023
- CVE-2017-688475Bu hafta
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %35zyxel · emg2926 firmware6 Nis 2017
- CVE-2024-4089171Bu hafta
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel V
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %22zyxel · vmg1312-b10a firmware4 Şub 2025
- CVE-2024-4089071Bu hafta
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %21zyxel · vmg1312-b10a firmware4 Şub 2025
- CVE-2024-1166770Bu hafta
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX seri
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %3zyxel · zld27 Kas 2024
- CVE-2022-034268Bu hafta
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series fi
KritikCVSS 9,8Kavram kanıtıEPSS %95zyxel · usg40 firmware28 Mar 2022
- CVE-2024-2997266Bu hafta
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions b
KritikCVSS 9,8Kavram kanıtıEPSS %89zyxel · nas326 firmware3 Haz 2024
- CVE-2026-727366Bu hafta
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %3zyxel · gs1900-8 firmware15 Haz 2026
- CVE-2024-2997365Bu hafta
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5
KritikCVSS 9,8Kavram kanıtıEPSS %86zyxel · nas326 firmware3 Haz 2024
- CVE-2021-403960Bu hafta
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS com
KritikCVSS 9,8Kavram kanıtıEPSS %71zyxel · nwa1100-nh firmware1 Mar 2022
- CVE-2023-3792853Planlayın
A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 fi
YüksekCVSS 8,8İstismar yokEPSS %60zyxel · nas326 firmware29 Kas 2023
- CVE-2023-447351Planlayın
A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(
KritikCVSS 9,8İstismar yokEPSS %41zyxel · nas326 firmware29 Kas 2023
- CVE-2023-3513851Planlayın
A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NA
KritikCVSS 9,8İstismar yokEPSS %40zyxel · nas326 firmware29 Kas 2023
- CVE-2019-1258349Planlayın
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest
KritikCVSS 9,1Kavram kanıtıEPSS %44zyxel · uag2100 firmware27 Haz 2019
- CVE-2023-447448Planlayın
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware
KritikCVSS 9,8İstismar yokEPSS %30zyxel · nas326 firmware29 Kas 2023
- CVE-2023-2877047Planlayın
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to
YüksekCVSS 7,5SilahlaştırılmışEPSS %58zyxel · dx5401-b0 firmware27 Nis 2023
- CVE-2024-2997446Planlayın
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versio
KritikCVSS 9,8İstismar yokEPSS %23zyxel · nas326 firmware3 Haz 2024
- CVE-2017-1837146Planlayın
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two
KritikCVSS 9,8SilahlaştırılmışEPSS %23zyxel · p660hn-t1a v2 firmware2 May 2019