CVE•Published 2026-05-12•Modified 2026-05-13•0 articles on news•5 live references•NVD data
CVE-2026-7255Zyxel · Wre6505_firmware
Vulnerability data via NVD (ingested)
CVSS v3.1
6.5
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS percentile
—
Weaknesses (CWE)
Description
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to brute-force the password and bypass authentication.
Timeline
Published 2026-05-12
Modified 2026-05-13
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-7255Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · OS
os:"Wre6505 Firmware"Hosts Shodan identified as running Wre6505 Firmware.
More intel sources (5)
Shodan report
vuln:CVE-2026-7255Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-7255Censys host search filtered to this CVE id.
grep.app
CVE-2026-7255Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-7255GitHub code search for direct mentions.
Google dork
"CVE-2026-7255" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (3)
CVE-2026-72553 repos
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
Correia-jpv/fucking-awesome-javaunknown
A curated list of awesome frameworks, libraries and software for the Java programming language. With repository stars⭐ and forks🍴
rxerium/CISA-KEVPython
An automated repo to track Nuclei template scanning capabilities against the CISA KEV.
We haven't classified any articles referencing CVE-2026-7255 yet. The external references above still apply.