CVE Tools

EX5401-B0 Firmware

20 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for EX5401-B0 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

EX5401-B0 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
EX5401-B0 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-122
2025-010
2025-020
2025-032
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-112
2025-120
2026-010
2026-020
2026-030
2026-041
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High630%
  • Medium1470%

Latest CVEs

The 15 most recently published vulnerabilities affecting EX5401-B0 Firmware.

  1. CVE-2026-0711A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with...6.8
  2. CVE-2025-8693A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute opera...8.8
  3. CVE-2025-6599An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑o...5.3
  4. CVE-2024-12010A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attac...7.2
  5. CVE-2024-12009A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with adminis...7.2
  6. CVE-2024-9197A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated atta...4.9
  7. CVE-2024-8748A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temp...7.5
  8. CVE-2024-38269An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenti...4.9
  9. CVE-2024-38268An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated ...4.9
  10. CVE-2024-38267An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticated...4.9
  11. CVE-2024-38266An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 could allow an authenticat...4.9
  12. CVE-2024-5412A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditi...7.5
  13. CVE-2024-0816The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI comm...5.5
  14. CVE-2023-37929The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by...6.5
  15. CVE-2022-43392A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) condit...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store