Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15329

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15330

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15333

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Use…

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15334

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15337

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15338

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15342

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15343

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15344

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15345

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15346

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15325

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15326

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.

No fix yet
Fix from $1,600 2022-09-29
Gs1900 8 Firmware MEDIUM 5.9
CVE-2022-34746

An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxe…

Fix: 2.70+
Fix from $1,600 2022-09-20
Nas326 Firmware CRITICAL 9.8
CVE-2022-34747

A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code…

Fix: 5.21+
Fix from $2,300 2022-09-06
Usg Flex 100w Firmware HIGH 7.8
CVE-2022-30526

A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 fir…

Fix: after 5.30
Fix from $1,950 2022-07-19
Usg Flex 100w Firmware MEDIUM 6.5
CVE-2022-2030

A directory traversal vulnerability caused by specific character sequences within an improperly sanitized URL was identified in some CGI programs of …

Fix: after 5.30
Fix from $1,600 2022-07-19
Gs1200 5 Firmware MEDIUM 6.2
CVE-2022-0823

An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by usin…

Fix: 2.00+
Fix from $1,600 2022-06-09
Vpn100 Firmware HIGH 7.8
CVE-2022-26531EPSS 6%

Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLE…

Fix: after 5.21
Fix from $1,950 2022-05-24
Vpn100 Firmware HIGH 7.8
CVE-2022-26532

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series …

Fix: after 5.21
Fix from $1,950 2022-05-24
Vpn100 Firmware MEDIUM 6.5
CVE-2022-0910

A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions…

Fix: after 5.21
Fix from $1,600 2022-05-24
Vpn100 Firmware MEDIUM 6.1
CVE-2022-0734EPSS 9%

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX serie…

Fix: after 5.20
Fix from $1,600 2022-05-24
Usg Flex 100w Firmware CRITICAL 9.8
CVE-2022-30525 KEVEPSS 100%

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware v…

Fix: 5.30+
Fix from $2,300 2022-05-12
Vmg3312 T20a Firmware HIGH 8.0
CVE-2022-26413

A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker…

Fix: 5.13 / 5.17+
Fix from $1,950 2022-04-11
Vmg3312 T20a Firmware MEDIUM 5.5
CVE-2022-26414

A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which coul…

Fix: 5.13 / 5.17+
Fix from $1,600 2022-04-11
Zyxel Ap Configurator HIGH 7.8
CVE-2022-0556

A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1…

Mitigation only
Fix from $1,950 2022-04-11
Usg40 Firmware CRITICAL 9.8
CVE-2022-0342EPSS 84%

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware ve…

Fix: 4.71+
Fix from $2,300 2022-03-28
Zywall 2 Plus Internet Security Appliance Firmware MEDIUM 6.1
CVE-2021-46387EPSS 21%

ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction…

No fix yet
Fix from $1,600 2022-03-01
Nwa1100 Nh Firmware CRITICAL 9.8
CVE-2021-4039EPSS 71%

A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on …

Fix: 2.12+
Fix from $2,300 2022-03-01
Ax7501 B0 Firmware MEDIUM 6.5
CVE-2021-35036

A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to…

Fix: 5.17 / 5.40+
Fix from $1,600 2022-03-01