Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15312

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15313

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15314

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15335

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.

Mitigation only
Fix from $1,950 2020-06-26
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15336

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.

Mitigation only
Fix from $1,950 2020-06-26
Cloud Cnm Secumanager CRITICAL 9.8
CVE-2020-15348

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c…

No fix yet
Fix from $2,300 2020-06-26
Wap6806 Firmware HIGH 8.6
CVE-2020-14461EPSS 10%

Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.

No fix yet
Fix from $1,950 2020-06-22
Xgs2210 52hp Firmware MEDIUM 5.4
CVE-2019-13495

In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitra…

No fix yet
Fix from $1,600 2020-03-31
Nas326 Firmware CRITICAL 9.8
CVE-2020-9054 KEVEPSS 100%

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi…

Fix: 4.35 / 5.21+
Fix from $2,300 2020-03-04
Gs1900 8 Firmware CRITICAL 9.8
CVE-2019-15800

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()…

Fix: 2.50+
Fix from $2,300 2019-11-14
Gs1900 8 Firmware CRITICAL 9.1
CVE-2019-15803

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented fun…

Fix: 2.50+
Fix from $2,300 2019-11-14
Gs1900 8 Firmware HIGH 8.8
CVE-2019-15799

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w…

Fix: 2.50+
Fix from $1,950 2019-11-14
Gs1900 8 Firmware HIGH 7.5
CVE-2019-15801

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to…

Fix: 2.50+
Fix from $1,950 2019-11-14
Gs1900 8 Firmware HIGH 7.5
CVE-2019-15804

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionali…

Fix: 2.50+
Fix from $1,950 2019-11-14
Gs1900 8 Firmware MEDIUM 5.9
CVE-2019-15802

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry…

Fix: 2.50+
Fix from $1,600 2019-11-14
2.00\(abbx.3\) MEDIUM 6.5
CVE-2019-15815

ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized us…

Patch available
Fix from $1,600 2019-11-12
Nbg 418n V2 Firmware CRITICAL 9.4
CVE-2019-17354

wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure…

Mitigation only
Fix from $2,300 2019-10-09
Uag2100 Firmware MEDIUM 6.1
CVE-2019-12581EPSS 6%

A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows r…

Fix: after 4.30
Fix from $1,600 2019-06-27
Uag2100 Firmware CRITICAL 9.1
CVE-2019-12583EPSS 44%

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts…

Fix: after 4.33
Fix from $2,300 2019-06-27
P 660hn T1 Firmware CRITICAL 9.8
CVE-2019-6725

The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm…

Mitigation only
Fix from $2,300 2019-05-31
Atp200 Firmware MEDIUM 6.1
CVE-2019-9955EPSS 21%

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 1…

Patch available
Fix from $1,600 2019-04-22
Nas326 Firmware HIGH 8.8
CVE-2019-10630

A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.

Fix: after 5.21
Fix from $1,950 2019-04-09
Nas326 Firmware HIGH 8.8
CVE-2019-10631

Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary …

Fix: after 5.21
Fix from $1,950 2019-04-09
Nas326 Firmware HIGH 8.8
CVE-2019-10633

An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t…

Fix: after 5.21
Fix from $1,950 2019-04-09
Nas326 Firmware MEDIUM 6.5
CVE-2019-10632

A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to chang…

Fix: after 5.21
Fix from $1,600 2019-04-09
Nas326 Firmware MEDIUM 5.4
CVE-2019-10634

An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via th…

Fix: after 5.21
Fix from $1,600 2019-04-09
Dsl 491hnu B10b Firmware HIGH 8.8
CVE-2019-7391EPSS 14%

ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-21
Nbg 418n Firmware HIGH 8.8
CVE-2019-6710

Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.

No fix yet
Fix from $1,950 2019-03-07
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14892

Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi…

No fix yet
Fix from $1,950 2018-11-27
Nsa325 V2 Firmware HIGH 8.8
CVE-2018-14893

A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…

No fix yet
Fix from $1,950 2018-11-27