Zyxel
zyxel
326 CVEs • 881 products
Products (881)
Click to collapseToggle
Products (881)
Click to collapse
CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100-N customized firmwar...Show more |
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator pr...Show more |
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) comma...Show more |
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent atta...Show more |
1Zyxel 6Dx5401 B1 Firmware Emg3525 T50b FirmwareEmg5523 T50b Firmware+3 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with adminis...Show more |
1Zyxel 52Am7510 00 Firmware Ax7501 B1 FirmwareDm4200 B0 Firmware+49 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (O...Show more |
1Zyxel 18Dx4510 B0 Firmware Dx4510 B1 FirmwareEe6510 10 Firmware+15 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by s...Show more |
1Zyxel 48Ax7501 B1 Firmware Dx3300 T0 FirmwareDx3300 T1 Firmware+45 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow a...Show more |
1Zyxel 54Ax7501 B1 Firmware Dx3300 T0 FirmwareDx3300 T1 Firmware+51 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow...Show more |
1Zyxel 54Ax7501 B1 Firmware Dx3300 T0 FirmwareDx3300 T1 Firmware+51 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could a...Show more |
1Zyxel 54Ax7501 B1 Firmware Dx3300 T0 FirmwareDx3300 T1 Firmware+51 moreFeb 25, 2026 Feb 24, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 c...Show more |
1Zyxel 54Ax7501 B0 Firmware Ax7501 B1 FirmwareDm4200 B0 Firmware+51 moreDec 15, 2025 Nov 18, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) comman...Show more |
1Zyxel 66Ax7501 B0 Firmware Ax7501 B1 FirmwareDm4200 B0 Firmware+63 moreDec 16, 2025 Nov 18, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Su...Show more |
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions from V4.16 through...Show more |
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) series firmware versions fr...Show more |
1Zyxel 24Emg3525 T50b Firmware Emg5523 T50b FirmwareEmg5723 T50k Firmware+21 moreJan 14, 2026 Jul 16, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditi...Show more |
1Zyxel 23Nwa110ax Firmware Nwa1123ac Pro FirmwareNwa130be Firmware+20 moreJan 14, 2026 Jul 15, 2025 N/A· v4 7.2 HIGH· v3 N/A· v2 A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator privileges to access specific dire...Show more |
**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges...Show more |
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to u...Show more |
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to...Show more |