Vulnerability index

Browse CVEs

117 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-7256 ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow… Wre6505 Firmware Mitigation only Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-7287 ** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert… Nwa1100 N Firmware Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-7255 ** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel W… Wre6505 Firmware Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.7 CVE-2026-6058 ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C… Wre6505 Firmware Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.7 CVE-2025-1732 An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could a… Uos Mitigation only Fix from $1,6002025-04-22 CRITICAL 9.8 CVE-2025-0890EPSS 14% **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAF… Vmg4325 B10a Firmware Mitigation only Fix from $2,3002025-02-04 HIGH 8.8 CVE-2024-40890 KEVEPSS 22% **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmw… Vmg1312 B10a Firmware Mitigation only Fix from $1,9502025-02-04 HIGH 8.8 CVE-2024-40891 KEVEPSS 22% **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B1… Vmg1312 B10a Firmware Mitigation only Fix from $1,9502025-02-04 HIGH 7.5 CVE-2024-11494 **UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could … P6101c Firmware No fix yet Fix from $1,9502024-11-20 CRITICAL 9.8 CVE-2024-8234 ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NW… Nwaw1100 N Firmware No fix yet Fix from $2,3002024-08-30 MEDIUM 6.5 CVE-2023-37929 The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacke… Dx3300 T1 Firmware Mitigation only Fix from $1,6002024-05-21 MEDIUM 5.5 CVE-2024-0816 The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of se… Lte3202 M437 Firmware Mitigation only Fix from $1,6002024-05-21 HIGH 7.5 CVE-2023-43314 ** UNSUPPORTED WHEN ASSIGNED **The buffer overflow vulnerability in the Zyxel PMG2005-T20B firmware version V1.00(ABNK.2)b11_C0 could allow an unauth… Pmg2005 T20b Firmware Mitigation only Fix from $1,9502023-09-27 MEDIUM 6.7 CVE-2022-45853 The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could… Gs1900 8 Firmware Mitigation only Fix from $1,6002023-05-30 CRITICAL 9.8 CVE-2023-22920 A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration… Lte3202 M437 Firmware Mitigation only Fix from $2,3002023-02-21 CRITICAL 9.8 CVE-2020-15331 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 CRITICAL 9.8 CVE-2020-15332 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 CRITICAL 9.8 CVE-2020-15347 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 HIGH 7.5 CVE-2020-15327 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 HIGH 7.5 CVE-2020-15340 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 HIGH 7.5 CVE-2020-15341 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 MEDIUM 6.1 CVE-2020-15339 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15328 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15329 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15330 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15333 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Use… Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15334 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15337 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15338 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15342 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29