Vulnerabilidades em Zyxel

169 resultados
Análise Vexday

Com 8 CVEs confirmadas em exploração ativa pelo CISA KEV em um universo de 162 catalogadas, a taxa de exploração da Zyxel é 11 vezes superior à média geral do catálogo, o que indica que os dispositivos dessa fabricante atraem interesse concreto de agentes maliciosos, não apenas teórico. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que permite execução arbitrária de comandos e costuma resultar em comprometimento total do equipamento. A CVE mais crítica ativa no momento, CVE-2022-30525, registra EPSS de 0,9994 — probabilidade de exploração próxima ao máximo da escala —, sinalizando risco iminente para ambientes que ainda não aplicaram a correção correspondente. Os 23 itens de severidade crítica e as 11 CVEs surgidas nos últimos 90 dias reforçam a necessidade de ciclos de patching contínuos e prioritários para qualquer organização que opere equipamentos Zyxel.

CVE-2023-35137HIGHAn improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwEPSS 0.9%CVE-2026-0711MEDIUMA post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.EPSS 0.8%CVE-2023-22920CRITICALA security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfEPSS 0.8%CVE-2023-22924MEDIUMA buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attaEPSS 0.8%CVE-2023-22923MEDIUMA format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authentiEPSS 0.8%CVE-2025-11845MEDIUMA null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(EPSS 0.8%CVE-2023-22918MEDIUMA post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEEPSS 0.8%CVE-2023-34139HIGHA command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 PatEPSS 0.8%CVE-2021-4029HIGHA command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commaEPSS 0.7%CVE-2022-43391MEDIUMA buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an EPSS 0.7%CVE-2022-0910MEDIUMA downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmwareEPSS 0.7%CVE-2024-8881MEDIUMA post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and EPSS 0.7%CVE-2026-8508MEDIUMAn improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 couEPSS 0.7%CVE-2022-26413HIGHA command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticatedEPSS 0.7%CVE-2023-22916HIGHThe configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FEPSS 0.7%CVE-2023-34141HIGHA command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 PaEPSS 0.7%CVE-2023-34138HIGHA command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USGEPSS 0.7%CVE-2024-11494HIGH**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_201403EPSS 0.7%CVE-2024-5412HIGHA buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenEPSS 0.7%CVE-2023-43314HIGH** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow EPSS 0.7%