Vulnerability index

Browse CVEs

117 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wre6505 Firmware HIGH 8.8
CVE-2026-7256

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow…

Mitigation only
Fix from $1,950 2026-05-12
Nwa1100 N Firmware HIGH 7.5
CVE-2026-7287

** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert…

Mitigation only
Fix from $1,950 2026-05-12
Wre6505 Firmware MEDIUM 6.5
CVE-2026-7255

** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel W…

Mitigation only
Fix from $1,600 2026-05-12
Wre6505 Firmware MEDIUM 5.7
CVE-2026-6058

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C…

Mitigation only
Fix from $1,600 2026-04-21
Uos MEDIUM 6.7
CVE-2025-1732

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could a…

Mitigation only
Fix from $1,600 2025-04-22
Vmg4325 B10a Firmware CRITICAL 9.8
CVE-2025-0890EPSS 14%

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF…

Mitigation only
Fix from $2,300 2025-02-04
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40890 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw…

Mitigation only
Fix from $1,950 2025-02-04
Vmg1312 B10a Firmware HIGH 8.8
CVE-2024-40891 KEVEPSS 22%

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1…

Mitigation only
Fix from $1,950 2025-02-04
P6101c Firmware HIGH 7.5
CVE-2024-11494

**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could …

No fix yet
Fix from $1,950 2024-11-20
Nwaw1100 N Firmware CRITICAL 9.8
CVE-2024-8234

** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NW…

No fix yet
Fix from $2,300 2024-08-30
Dx3300 T1 Firmware MEDIUM 6.5
CVE-2023-37929

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacke…

Mitigation only
Fix from $1,600 2024-05-21
Lte3202 M437 Firmware MEDIUM 5.5
CVE-2024-0816

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of se…

Mitigation only
Fix from $1,600 2024-05-21
Pmg2005 T20b Firmware HIGH 7.5
CVE-2023-43314

** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauth…

Mitigation only
Fix from $1,950 2023-09-27
Gs1900 8 Firmware MEDIUM 6.7
CVE-2022-45853

The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could…

Mitigation only
Fix from $1,600 2023-05-30
Lte3202 M437 Firmware CRITICAL 9.8
CVE-2023-22920

A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration…

Mitigation only
Fix from $2,300 2023-02-21
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15331

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15332

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15347

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15327

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15340

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15341

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager MEDIUM 6.1
CVE-2020-15339

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15328

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15329

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15330

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15333

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Use…

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15334

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15337

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15338

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15342

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

No fix yet
Fix from $1,600 2022-09-29