cbcvebase.

Zyxel Wre6505 Firmware vulnerabilities

5 known vulnerabilities affecting zyxel/wre6505_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2017-7964P2CRITICALCVSS 10.0≤ v1.00\(aaqb.3\)c02017-04-19
CVE-2017-7964 [CRITICAL] CWE-1188 CVE-2017-7964: Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.
nvd
CVE-2026-7256P3HIGHCVSS 8.8vv1.00\(abdv.3\)c02026-05-12
CVE-2026-7256 [HIGH] CWE-78 CVE-2026-7256: ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE650 ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP request.
nvd
CVE-2026-7255P3MEDIUMCVSS 6.5vv1.00\(abdv.3\)c02026-05-12
CVE-2026-7255 [MEDIUM] CWE-307 CVE-2026-7255: ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnera ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication.
nvd
CVE-2026-6058P4MEDIUMCVSS 5.7vv1.00\(abdv.3\)c02026-04-21
CVE-2026-6058 [MEDIUM] CWE-116 CVE-2026-6058: ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticated administrator to visit the “AP Select” page while
nvd
CVE-2026-7257P4MEDIUMCVSS 4.4vv1.00\(abdv.3\)c02026-05-12
CVE-2026-7257 [MEDIUM] CWE-922 CVE-2026-7257: ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the co ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker with administrator privileges to download and decrypt a backup configuration file.
nvd
Zyxel Wre6505 Firmware vulnerabilities | cvebase