CVE-2025-8693
- EPSS 0.23%
- Veröffentlicht 18.11.2025 01:25:05
- Zuletzt bearbeitet 15.12.2025 14:03:35
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.
CVE-2025-6599
- EPSS 0.06%
- Veröffentlicht 18.11.2025 01:19:47
- Zuletzt bearbeitet 16.12.2025 21:19:59
An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily blo...
CVE-2024-12009
- EPSS 0.32%
- Veröffentlicht 11.03.2025 02:15:10
- Zuletzt bearbeitet 13.01.2026 15:54:51
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) co...
CVE-2024-12010
- EPSS 0.32%
- Veröffentlicht 11.03.2025 02:15:10
- Zuletzt bearbeitet 13.01.2026 16:19:21
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating syst...
CVE-2024-8748
- EPSS 0.95%
- Veröffentlicht 03.12.2024 02:15:17
- Zuletzt bearbeitet 21.01.2025 21:20:19
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the w...
CVE-2024-9197
- EPSS 0.39%
- Veröffentlicht 03.12.2024 02:15:17
- Zuletzt bearbeitet 21.01.2025 21:18:24
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporar...
CVE-2023-37929
- EPSS 1.46%
- Veröffentlicht 21.05.2024 02:15:08
- Zuletzt bearbeitet 22.01.2025 22:55:02
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable devic...
CVE-2024-0816
- EPSS 0.09%
- Veröffentlicht 21.05.2024 02:15:08
- Zuletzt bearbeitet 22.01.2025 22:58:56
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
CVE-2022-43390
- EPSS 2.5%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:23
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
CVE-2022-43391
- EPSS 1.42%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:23
A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.