Skip to main content

Vendor/product archive

zyxel / usg_flex_100ax CVEs

Beta · best-effort

14 CVEs tagged to zyxel / usg_flex_100ax0 Critical, 10 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-9133

Published Oct 21, 2025

A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, USG FLEX 50(W) se…

CVSS 8.1 · High

CVE-2025-8078

Published Oct 21, 2025

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.40, U…

CVSS 7.2 · High

CVE-2024-11667

Published Nov 27, 2024

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.3…

CVSS 7.5 · High
evidence mentions
4
Buzz score
57.6
KEV listed

CVE-2024-42061

Published Sep 3, 2024

A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmwa…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-7203

Published Sep 3, 2024

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-6343

Published Sep 3, 2024

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-42060

Published Sep 3, 2024

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, U…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-42059

Published Sep 3, 2024

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, U…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-42058

Published Sep 3, 2024

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W)…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-42057

Published Sep 3, 2024

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.…

CVSS 8.1 · High
evidence mentions
5
Buzz score
25.9
Showing 1-14 of 14 CVEsPage 1 of 1