Vulnerabilidades em Zyxel

169 resultados
Análise Vexday

Com 8 CVEs confirmadas em exploração ativa pelo CISA KEV em um universo de 162 catalogadas, a taxa de exploração da Zyxel é 11 vezes superior à média geral do catálogo, o que indica que os dispositivos dessa fabricante atraem interesse concreto de agentes maliciosos, não apenas teórico. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que permite execução arbitrária de comandos e costuma resultar em comprometimento total do equipamento. A CVE mais crítica ativa no momento, CVE-2022-30525, registra EPSS de 0,9994 — probabilidade de exploração próxima ao máximo da escala —, sinalizando risco iminente para ambientes que ainda não aplicaram a correção correspondente. Os 23 itens de severidade crítica e as 11 CVEs surgidas nos últimos 90 dias reforçam a necessidade de ciclos de patching contínuos e prioritários para qualquer organização que opere equipamentos Zyxel.

CVE-2024-38267MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware verEPSS 0.4%CVE-2024-38266MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware vEPSS 0.4%CVE-2024-38269MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmwarEPSS 0.4%CVE-2024-38268MEDIUMAn improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versEPSS 0.4%CVE-2021-35033HIGHA vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password managemEPSS 0.4%CVE-2023-28767HIGHThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX serieEPSS 0.4%CVE-2022-34746MEDIUMAn insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was founEPSS 0.4%CVE-2022-40603MEDIUMA cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firEPSS 0.4%CVE-2022-0556HIGHA local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) EPSS 0.4%CVE-2026-14818HIGHA path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 throuEPSS 0.4%CVE-2022-45441MEDIUMA cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker tEPSS 0.4%CVE-2023-27990MEDIUMThe cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50EPSS 0.3%CVE-2023-33011HIGHA format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 thEPSS 0.3%CVE-2024-1575MEDIUMThe improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an autheEPSS 0.3%CVE-2025-6599MEDIUMAn uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could EPSS 0.3%CVE-2024-42061MEDIUMA reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.3EPSS 0.3%CVE-2026-7287HIGH** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and foEPSS 0.3%CVE-2021-35028HIGHA command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to exEPSS 0.3%CVE-2023-28768MEDIUMImproper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1), and XS1930-10 firEPSS 0.3%CVE-2023-6397MEDIUM A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX serieEPSS 0.3%