Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2020-15343
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15344
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15345
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15346
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15325
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15326
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
Cloudcnm Secumanager
No fix yet
HIGH 7.8
CVE-2022-0556
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1…
Zyxel Ap Configurator
Mitigation only
MEDIUM 6.1
CVE-2021-46387EPSS 21%
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction…
Zywall 2 Plus Internet Security Appliance Firmware
No fix yet
CRITICAL 9.1
CVE-2020-28899
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via …
Lte4506 M606 Firmware
Mitigation only
HIGH 7.8
CVE-2021-3297EPSS 21%
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
Nbg2105 Firmware
No fix yet
CRITICAL 9.8
CVE-2020-29583 KEVEPSS 90%
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can …
Usg20 Vpn Firmware
Mitigation only
HIGH 7.5
CVE-2020-20183
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil…
P1302 T10 V3 Firmware
Mitigation only
HIGH 8.8
CVE-2020-13364
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3…
Nas326 Firmware
Mitigation only
HIGH 8.8
CVE-2020-13365
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can …
Nas326 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-15320
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15321
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15322
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15323
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15324
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.
Cloud Cnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15315
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15316
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15317
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15318
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15319
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15312
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15313
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15314
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
HIGH 7.5
CVE-2020-15335
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Cloudcnm Secumanager
Mitigation only
HIGH 7.5
CVE-2020-15336
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Cloudcnm Secumanager
Mitigation only
CRITICAL 9.8
CVE-2020-15348
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c…
Cloud Cnm Secumanager
No fix yet