Tz80
Vendor:
First CVE: Jan 9, 2025 · Active for 1 year
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Tz80 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2025
18 months ago
Most Recent CVE
Apr 29, 2026
88 days ago
CVE Severity & Scoring
Tz8010 CVEs
70%
20%
10%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (20.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low0 (0.0%)
High6 (60.0%)
None4 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-53704CRITICAL An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | Jan 9, 2025 | 9.8 | 98 | YES | YES |
CVE-2026-0204HIGH A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. | Apr 29, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-0205MEDIUM A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. | Apr 29, 2026 | 6.8 | 30 | NO | NO |
CVE-2025-40601HIGH A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted f | Nov 20, 2025 | 7.5 | 29 | NO | NO |
CVE-2026-0206MEDIUM A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. | Apr 29, 2026 | 4.9 | 25 | NO | NO |
CVE-2026-0400MEDIUM A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall. | Feb 24, 2026 | 4.9 | 22 | NO | NO |
CVE-2026-3439MEDIUM A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall. | Mar 4, 2026 | 4.9 | 20 | NO | NO |
CVE-2026-0402MEDIUM A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall. | Feb 24, 2026 | 4.9 | 19 | NO | NO |
CVE-2026-0401MEDIUM A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall. | Feb 24, 2026 | 4.9 | 19 | NO | NO |
CVE-2026-0399MEDIUM Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint. | Feb 24, 2026 | 4.9 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
1 CVE
10.0% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CWEs
Versions
No cataloged versions.