Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nbg6816 Firmware HIGH 8.8
CVE-2021-4029

A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a…

Fix: 1.00+
Fix from $1,950 2022-02-24
Nbg6816 Firmware HIGH 8.8
CVE-2021-4030

A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands…

Fix: 1.00+
Fix from $1,950 2022-02-24
Nbg6604 Firmware CRITICAL 9.1
CVE-2021-35034

An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device …

Fix: 1.00+
Fix from $2,300 2021-12-29
Nbg6604 Firmware MEDIUM 6.5
CVE-2021-35035

A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensi…

Fix: 1.00+
Fix from $1,600 2021-12-29
Gs1900 8 Firmware HIGH 8.0
CVE-2021-35031

A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authen…

Fix: 2.70+
Fix from $1,950 2021-12-28
Gs1900 8 Firmware HIGH 7.8
CVE-2021-35032

A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS c…

Fix: 2.70+
Fix from $1,950 2021-12-28
Nbg6818 Firmware HIGH 7.8
CVE-2021-35033

A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could…

Fix: 1.00 / 2.20+
Fix from $1,950 2021-11-23
Zywall Vpn2s Firmware HIGH 7.8
CVE-2021-35028

A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arb…

Patch available
Fix from $1,950 2021-09-29
Zywall Vpn2s Firmware HIGH 7.5
CVE-2021-35027

A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensit…

Patch available
Fix from $1,950 2021-09-29
Usg1900 Firmware CRITICAL 9.8
CVE-2021-35029

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG …

Fix: after 4.64
Fix from $2,300 2021-07-02
Lte4506 M606 Firmware CRITICAL 9.1
CVE-2020-28899

The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via …

Mitigation only
Fix from $2,300 2021-03-16
Nbg2105 Firmware HIGH 7.8
CVE-2021-3297EPSS 21%

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

No fix yet
Fix from $1,950 2021-01-26
Vpn Orchestrator HIGH 7.2
CVE-2020-29299

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-pr…

Fix: 1.33 / 4.39+
Fix from $1,950 2020-12-27
Usg20 Vpn Firmware CRITICAL 9.8
CVE-2020-29583 KEVEPSS 90%

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can …

Mitigation only
Fix from $2,300 2020-12-22
P1302 T10 V3 Firmware HIGH 7.5
CVE-2020-20183

Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil…

Mitigation only
Fix from $1,950 2020-12-14
Zld CRITICAL 9.8
CVE-2020-25014

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows r…

Fix: after 6.10
Fix from $2,300 2020-11-27
Vmg5313 B30b Firmware CRITICAL 9.8
CVE-2020-24355

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows …

Fix: after 5.13
Fix from $2,300 2020-09-02
Vmg5313 B30b Firmware HIGH 8.8
CVE-2020-24354

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.

Fix: after 5.13
Fix from $1,950 2020-08-31
Nas326 Firmware HIGH 8.8
CVE-2020-13364

A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3…

Mitigation only
Fix from $1,950 2020-08-06
Nas326 Firmware HIGH 8.8
CVE-2020-13365

Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can …

Mitigation only
Fix from $1,950 2020-08-06
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15320

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15321

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15322

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15323

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

No fix yet
Fix from $2,300 2020-06-29
Cloud Cnm Secumanager CRITICAL 9.8
CVE-2020-15324

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15315

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15316

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15317

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15318

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15319

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29