Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-7256
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow…
Wre6505 Firmware
Mitigation only
HIGH 7.5
CVE-2026-7287
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert…
Nwa1100 N Firmware
Mitigation only
MEDIUM 6.5
CVE-2026-7255
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel W…
Wre6505 Firmware
Mitigation only
HIGH 7.2
CVE-2026-1460
A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 f…
Nebula Fwa70 Firmware
1.15 / 1.16+
MEDIUM 6.8
CVE-2026-0711
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 coul…
Nr5307 Firmware
1.60 / 2.00+
MEDIUM 5.7
CVE-2026-6058
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C…
Wre6505 Firmware
Mitigation only
CRITICAL 9.8
CVE-2025-13942
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attack…
Wx5610 B0 Firmware
1.00 / 1.16+
HIGH 8.8
CVE-2025-13943
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)…
Ex5601 T1 Firmware
5.17 / 5.18+
HIGH 7.2
CVE-2026-1459
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions thro…
Vmg3625 T50c Firmware
after 5.50
HIGH 8.8
CVE-2025-8693
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could …
Dm4200 B0 Firmware
after 5.63
HIGH 7.5
CVE-2025-6599
An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an …
Lte3301 Plus Firmware
after 5.00
HIGH 8.1
CVE-2025-9133EPSS 5%
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 th…
Zld
5.41+
HIGH 7.2
CVE-2025-8078
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versio…
Zld
5.41+
CRITICAL 9.8
CVE-2025-7673
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could all…
Emg3525 T50b Firmware
5.13 / 5.15+
HIGH 7.2
CVE-2025-6265
A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authe…
Nwa50ax Firmware
after 7.10
HIGH 7.8
CVE-2025-1731
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V…
Uos
1.32+
MEDIUM 6.7
CVE-2025-1732
An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could a…
Uos
Mitigation only
HIGH 7.2
CVE-2024-11253
A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmware vers…
Emg5723 T50k Firmware
after 5.50
HIGH 7.2
CVE-2024-12009
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier co…
Dx3300 T0 Firmware
after 5.50
HIGH 7.2
CVE-2024-12010
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and …
Wx5610 B0 Firmware
after 5.50
CRITICAL 9.8
CVE-2025-0890EPSS 14%
**UNSUPPORTED WHEN ASSIGNED**
Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF…
Vmg4325 B10a Firmware
Mitigation only
HIGH 8.8
CVE-2024-40890 KEVEPSS 22%
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw…
Vmg1312 B10a Firmware
Mitigation only
HIGH 8.8
CVE-2024-40891 KEVEPSS 22%
**UNSUPPORTED WHEN ASSIGNED**
A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1…
Vmg1312 B10a Firmware
Mitigation only
HIGH 8.8
CVE-2024-12398
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S…
Nwa50ax Firmware
7.10+
HIGH 7.5
CVE-2024-8748
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABO…
Lte3301 Plus Firmware
1.00 / 1.16+
HIGH 7.2
CVE-2024-9200
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions thro…
Emg6726 B10a Firmware
5.13 / 5.15+
CRITICAL 9.8
CVE-2024-11667 KEV
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmwa…
Zld
after 5.38
HIGH 7.5
CVE-2024-11494
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could …
P6101c Firmware
No fix yet
MEDIUM 6.8
CVE-2024-8881
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier c…
Gs1900 8 Firmware
2.90+
HIGH 7.8
CVE-2024-9677
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions co…
Uos
1.30+