Vulnerabilidades em Zyxel

169 resultados
Análise Vexday

Com 8 CVEs confirmadas em exploração ativa pelo CISA KEV em um universo de 162 catalogadas, a taxa de exploração da Zyxel é 11 vezes superior à média geral do catálogo, o que indica que os dispositivos dessa fabricante atraem interesse concreto de agentes maliciosos, não apenas teórico. O tipo de falha mais recorrente é CWE-78 (injeção de comandos no sistema operacional), categoria que permite execução arbitrária de comandos e costuma resultar em comprometimento total do equipamento. A CVE mais crítica ativa no momento, CVE-2022-30525, registra EPSS de 0,9994 — probabilidade de exploração próxima ao máximo da escala —, sinalizando risco iminente para ambientes que ainda não aplicaram a correção correspondente. Os 23 itens de severidade crítica e as 11 CVEs surgidas nos últimos 90 dias reforçam a necessidade de ciclos de patching contínuos e prioritários para qualquer organização que opere equipamentos Zyxel.

CVE-2022-45439MEDIUMA pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. EPSS 0.2%CVE-2026-6058MEDIUM** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00EPSS 0.2%CVE-2023-35140MEDIUMThe improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated EPSS 0.2%CVE-2022-45853MEDIUMThe privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHIEPSS 0.2%CVE-2026-3870MEDIUMA buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could EPSS 0.2%CVE-2026-3871MEDIUMA buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 couEPSS 0.2%CVE-2024-9677MEDIUMThe insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier veEPSS 0.2%CVE-2024-0816MEDIUMThe buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denEPSS 0.1%CVE-2026-7257MEDIUM** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firEPSS 0.1%