Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dx5401 B0 Firmware CRITICAL 9.8
CVE-2023-28769EPSS 5%

The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1…

Fix: 5.17+
Fix from $2,300 2023-04-27
Dx5401 B0 Firmware HIGH 7.5
CVE-2023-28770EPSS 58%

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(AB…

Fix: 5.17+
Fix from $1,950 2023-04-27
Atp100 Firmware CRITICAL 9.8
CVE-2023-28771 KEVEPSS 99%

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG F…

Fix: 5.35 / 5.36+
Fix from $2,300 2023-04-25
Atp200 Firmware HIGH 8.8
CVE-2023-27991

The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f…

Fix: 5.36+
Fix from $1,950 2023-04-24
Atp200 Firmware MEDIUM 6.5
CVE-2023-22918

A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series …

Fix: 5.36+
Fix from $1,600 2023-04-24
Usg Flex 100 Firmware HIGH 8.1
CVE-2023-22913

A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 throu…

Fix: after 5.35
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 8.1
CVE-2023-22916

The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W)…

Fix: after 5.35
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 7.5
CVE-2023-22915

A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) …

Fix: after 5.35
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 7.5
CVE-2023-22917

A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware ver…

Fix: after 5.35
Fix from $1,950 2023-04-24
Usg Flex 100 Firmware HIGH 7.2
CVE-2023-22914

A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series fi…

Fix: after 5.35
Fix from $1,950 2023-04-24
Lte3202 M437 Firmware CRITICAL 9.8
CVE-2023-22920

A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration…

Mitigation only
Fix from $2,300 2023-02-21
Atp100 Firmware HIGH 7.2
CVE-2022-38547

A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series f…

Fix: after 5.32
Fix from $1,950 2023-02-07
Nbg 418n Firmware MEDIUM 6.1
CVE-2022-45441

A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store m…

Fix: after 1.00
Fix from $1,600 2023-02-07
Ax7501 B0 Firmware MEDIUM 6.5
CVE-2022-45439

A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauth…

Fix: 5.17+
Fix from $1,600 2023-01-17
Lte3202 M437 Firmware CRITICAL 9.8
CVE-2022-43389

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthentica…

Fix: 1.00 / 1.15+
Fix from $2,300 2023-01-11
Lte7480 M804 Firmware HIGH 8.8
CVE-2022-43390

A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker t…

Fix: 1.00 / 1.15+
Fix from $1,950 2023-01-11
Gs1350 6hp Firmware HIGH 8.2
CVE-2022-43393

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C…

Fix: 4.70+
Fix from $1,950 2023-01-11
Lte3301 Plus Firmware MEDIUM 6.5
CVE-2022-43391

A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authentic…

Fix: 1.00+
Fix from $1,600 2023-01-11
Lte3301 Plus Firmware MEDIUM 6.5
CVE-2022-43392

A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated …

Fix: 1.00+
Fix from $1,600 2023-01-11
Nbg7510 Firmware CRITICAL 9.8
CVE-2022-38546

A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access…

Fix: after 1.00
Fix from $2,300 2022-12-21
Atp800 Firmware MEDIUM 6.1
CVE-2022-40603

A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware ver…

Fix: after 5.31
Fix from $1,600 2022-12-06
Lte3301 M209 Firmware CRITICAL 9.8
CVE-2022-40602

A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-…

Fix: 1.00+
Fix from $2,300 2022-11-22
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15331

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15332

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15347

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

No fix yet
Fix from $2,300 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15327

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15340

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15341

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager MEDIUM 6.1
CVE-2020-15339

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15328

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

No fix yet
Fix from $1,600 2022-09-29