Vulnerability index

Browse CVEs

117 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wap6806 Firmware HIGH 8.6
CVE-2020-14461EPSS 10%

Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.

No fix yet
Fix from $1,950 2020-06-22
Xgs2210 52hp Firmware MEDIUM 5.4
CVE-2019-13495

In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitra…

No fix yet
Fix from $1,600 2020-03-31
Nbg 418n V2 Firmware CRITICAL 9.4
CVE-2019-17354

wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure…

Mitigation only
Fix from $2,300 2019-10-09
P 660hn T1 Firmware CRITICAL 9.8
CVE-2019-6725

The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm…

Mitigation only
Fix from $2,300 2019-05-31
Dsl 491hnu B10b Firmware HIGH 8.8
CVE-2019-7391EPSS 14%

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-21
Nbg 418n Firmware HIGH 8.8
CVE-2019-6710

Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-07
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14892

Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi…

No fix yet
Fix from $1,950 2018-11-27
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14893

A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…

No fix yet
Fix from $1,950 2018-11-27
Zywall Usg 100 Firmware HIGH 8.8
CVE-2017-17550

ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This…

No fix yet
Fix from $1,950 2018-11-10
Vmg3312 B10b Firmware CRITICAL 9.8
CVE-2018-18754

ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

Mitigation only
Fix from $2,300 2018-10-29
Vmg3312 B10b Firmware MEDIUM 6.1
CVE-2018-15602

Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname para…

Mitigation only
Fix from $1,600 2018-08-26
Ac3000 Firmware MEDIUM 6.8
CVE-2018-9149

The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device …

No fix yet
Fix from $1,600 2018-04-01
P 870h 51 Firmware CRITICAL 9.8
CVE-2018-1164

This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.…

Mitigation only
Fix from $2,300 2018-02-21
P 660hw V3 Firmware HIGH 7.5
CVE-2018-5330

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.

No fix yet
Fix from $1,950 2018-01-16
P 660hw Firmware HIGH 7.5
CVE-2017-17901

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.

No fix yet
Fix from $1,950 2017-12-29
Nbg6716 Firmware CRITICAL 9.8
CVE-2017-15226

Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca…

No fix yet
Fix from $2,300 2017-10-10
Nwa1100 N Firmware MEDIUM 5.9
CVE-2015-7256

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, …

Mitigation only
Fix from $1,600 2017-09-28
Pk5001z Firmware HIGH 8.8
CVE-2016-10401EPSS 12%

ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwo…

No fix yet
Fix from $1,950 2017-07-25
Emg2926 Firmware HIGH 8.8
CVE-2017-6884 KEVEPSS 38%

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …

Mitigation only
Fix from $1,950 2017-04-06
Nbg 418n Firmware HIGH 8.0
CVE-2015-7284

Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authenti…

Mitigation only
Fix from $1,950 2015-12-31
Nbg 418n Firmware HIGH 8.1
CVE-2015-7283

The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which a…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware HIGH 8.0
CVE-2015-6020

ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware HIGH 8.5
CVE-2015-6019

The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote a…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware CRITICAL 9.8
CVE-2015-6018EPSS 21%

The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary com…

No fix yet
Fix from $2,300 2015-12-31
P 660hw T1 V2 Firmware MEDIUM 6.1
CVE-2015-6017

Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote atta…

Mitigation only
Fix from $1,600 2015-12-31
Nbg 418n CRITICAL 9.8
CVE-2015-6016EPSS 6%

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default passw…

Mitigation only
Fix from $2,300 2015-12-31
P 660hw MEDIUM 6.8
CVE-2014-4162

Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2014-06-16
N300 Netusb Nbg 419n Firmware HIGH 7.9
CVE-2014-0355

Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers…

Mitigation only
Fix from $1,950 2014-04-15
N300 Netusb Nbg 419n Firmware HIGH 7.9
CVE-2014-0356

The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters…

Mitigation only
Fix from $1,950 2014-04-15
N300 Netusb Nbg 419n Firmware HIGH 7.8
CVE-2014-0354

The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an unspecified account, which al…

Mitigation only
Fix from $1,950 2014-04-15