Vulnerabilities in Zyxel

169 results
Vexday analysis

Com 8 CVEs confirmadas em exploração ativa pelo CISA KEV em um universo de 162 catalogadas, a taxa de exploração da Zyxel é 11 vezes superior à média geral do catálogo, o que indica que os dispositivos dessa fabricante atraem interesse concreto de agentes maliciosos, não apenas teórico. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que permite execução arbitrária de comandos e costuma resultar em comprometimento total do equipamento. A CVE mais crítica ativa no momento, CVE-2022-30525, registra EPSS de 0,9994 — probabilidade de exploração próxima ao máximo da escala —, sinalizando risco iminente para ambientes que ainda não aplicaram a correção correspondente. Os 23 itens de severidade crítica e as 11 CVEs surgidas nos últimos 90 dias reforçam a necessidade de ciclos de patching contínuos e prioritários para qualquer organização que opere equipamentos Zyxel.

CVE-2023-6397MEDIUM A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%CVE-2023-34140MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 EPSS 0.3%CVE-2026-4795MEDIUMA missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.0EPSS 0.3%CVE-2022-45854MEDIUMAn improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to caEPSS 0.3%CVE-2021-35030LOWA vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and cEPSS 0.3%CVE-2026-3870MEDIUMA buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could EPSS 0.3%CVE-2026-3871MEDIUMA buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 couEPSS 0.3%CVE-2022-45440MEDIUMA vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on externaEPSS 0.2%CVE-2024-8882MEDIUMA buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow anEPSS 0.2%CVE-2023-35136MEDIUMAn improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX serEPSS 0.2%CVE-2023-4397MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series EPSS 0.2%CVE-2022-0823MEDIUMAn improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the passworEPSS 0.2%CVE-2023-37926MEDIUMA buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through EPSS 0.2%CVE-2023-37925MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%CVE-2026-6058MEDIUM** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00EPSS 0.2%CVE-2023-5960MEDIUMAn improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VEPSS 0.2%CVE-2023-5593HIGHThe out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software version 4.0.4.0 could allow an authenticatedEPSS 0.2%CVE-2023-5650MEDIUMAn improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmEPSS 0.2%CVE-2021-35032MEDIUMA vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitEPSS 0.2%CVE-2023-5797MEDIUMAn improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEEPSS 0.2%