VYPR

Pm7300 T0 Firmware

by Zyxel

CVEs (20)

  • CVE-2025-13943HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.01

    A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

  • CVE-2025-8693HigNov 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

  • CVE-2022-26413HigApr 11, 2022
    risk 0.52cvss 8.0epss 0.01

    A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.

  • CVE-2024-8748HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by…

  • CVE-2024-5412HigSep 3, 2024
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

  • CVE-2022-43392MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.

  • CVE-2022-43391MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.

  • CVE-2021-35036MedMar 1, 2022
    risk 0.42cvss 6.5epss 0.00

    A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.

  • CVE-2022-26414MedApr 11, 2022
    risk 0.39cvss 6.0epss 0.00

    A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service.

  • CVE-2024-0816MedMay 21, 2024
    risk 0.36cvss 5.5epss 0.00

    The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

  • CVE-2022-43390MedJan 11, 2023
    risk 0.35cvss 5.4epss 0.01

    A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.

  • CVE-2025-6599MedNov 18, 2025
    risk 0.34cvss 5.3epss 0.00

    An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service (DoS) attacks. Such attacks may temporarily block legitimate HTTP…

  • CVE-2025-11848MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.02

    A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to…

  • CVE-2025-11847MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.02

    A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator…

  • CVE-2025-11846MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.01

    A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator…

  • CVE-2025-11845MedFeb 24, 2026
    risk 0.32cvss 4.9epss 0.01

    A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator…

  • CVE-2024-38269MedSep 24, 2024
    risk 0.32cvss 4.9epss 0.00

    An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory…

  • CVE-2024-38268MedSep 24, 2024
    risk 0.32cvss 4.9epss 0.00

    An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions,…

  • CVE-2024-38267MedSep 24, 2024
    risk 0.32cvss 4.9epss 0.00

    An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions,…

  • CVE-2024-38266MedSep 24, 2024
    risk 0.32cvss 4.9epss 0.00

    An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated attacker with administrator privileges to cause potential memory corruptions,…