Vulnerabilities in Zyxel

169 results
Vexday analysis

Com 8 CVEs confirmadas em exploração ativa pelo CISA KEV em um universo de 162 catalogadas, a taxa de exploração da Zyxel é 11 vezes superior à média geral do catálogo, o que indica que os dispositivos dessa fabricante atraem interesse concreto de agentes maliciosos, não apenas teórico. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que permite execução arbitrária de comandos e costuma resultar em comprometimento total do equipamento. A CVE mais crítica ativa no momento, CVE-2022-30525, registra EPSS de 0,9994 — probabilidade de exploração próxima ao máximo da escala —, sinalizando risco iminente para ambientes que ainda não aplicaram a correção correspondente. Os 23 itens de severidade crítica e as 11 CVEs surgidas nos últimos 90 dias reforçam a necessidade de ciclos de patching contínuos e prioritários para qualquer organização que opere equipamentos Zyxel.

CVE-2023-37927HIGHThe improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwareEPSS 1.8%CVE-2022-34747CRITICALA format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized reEPSS 1.7%CVE-2023-33013HIGHA post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an auEPSS 1.7%CVE-2023-22919HIGHThe post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated aEPSS 1.6%CVE-2026-6837HIGHA post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4EPSS 1.5%CVE-2026-6952HIGHA post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions EPSS 1.5%CVE-2023-27991HIGHThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEXEPSS 1.5%CVE-2025-8078HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmwaEPSS 1.4%CVE-2025-11730HIGHA post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versiEPSS 1.4%CVE-2025-13943HIGHA post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.5EPSS 1.4%CVE-2023-27988HIGHThe post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an autheEPSS 1.4%CVE-2024-42060HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2024-42059HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2024-7203HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firEPSS 1.3%CVE-2023-6398HIGHA post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37EPSS 1.3%CVE-2024-42057HIGHA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series fEPSS 1.3%CVE-2022-2030MEDIUMA directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI proEPSS 1.3%CVE-2023-22913HIGHA post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4EPSS 1.3%CVE-2026-7273HIGHA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow aEPSS 1.3%KEVCVE-2025-11846MEDIUMA null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9EPSS 1.2%