Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vmg1312 B10d Firmware HIGH 7.5
CVE-2018-19326EPSS 10%

Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.

Fix: 5.13+
Fix from $1,950 2018-11-17
Zywall Usg 100 Firmware HIGH 8.8
CVE-2017-17550

ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This…

No fix yet
Fix from $1,950 2018-11-10
Vmg3312 B10b Firmware CRITICAL 9.8
CVE-2018-18754

ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

Mitigation only
Fix from $2,300 2018-10-29
Vmg3312 B10b Firmware MEDIUM 6.1
CVE-2018-15602

Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname para…

Mitigation only
Fix from $1,600 2018-08-26
Zywall 110 Firmware MEDIUM 5.9
CVE-2018-9129

ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec base…

Patch available
Fix from $1,600 2018-08-15
Ac3000 Firmware MEDIUM 6.8
CVE-2018-9149

The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device …

No fix yet
Fix from $1,600 2018-04-01
P 870h 51 Firmware CRITICAL 9.8
CVE-2018-1164

This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.…

Mitigation only
Fix from $2,300 2018-02-21
P 660hw V3 Firmware HIGH 7.5
CVE-2018-5330

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.

No fix yet
Fix from $1,950 2018-01-16
P 660hw Firmware HIGH 7.5
CVE-2017-17901

ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.

No fix yet
Fix from $1,950 2017-12-29
Nbg6716 Firmware CRITICAL 9.8
CVE-2017-15226

Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca…

No fix yet
Fix from $2,300 2017-10-10
Nwa1100 N Firmware MEDIUM 5.9
CVE-2015-7256

ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, …

Mitigation only
Fix from $1,600 2017-09-28
Pk5001z Firmware HIGH 8.8
CVE-2016-10401EPSS 12%

ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwo…

No fix yet
Fix from $1,950 2017-07-25
Wre6505 Firmware CRITICAL 10.0
CVE-2017-7964

Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct D…

Patch available
Fix from $2,300 2017-04-19
Emg2926 Firmware HIGH 8.8
CVE-2017-6884 KEVEPSS 38%

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …

Mitigation only
Fix from $1,950 2017-04-06
Usg50 Firmware HIGH 7.5
CVE-2016-10227

Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4…

Patch available
Fix from $1,950 2017-02-21
Gs1900 10hp Firmware HIGH 7.5
CVE-2015-6260

Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause…

Fix: 2.50+
Fix from $1,950 2016-03-03
Gs1900 10hp Firmware MEDIUM 5.4
CVE-2016-1307

The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it e…

Fix: 2.50+
Fix from $1,600 2016-02-07
Gs1900 10hp Firmware HIGH 7.5
CVE-2015-6398

Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of ser…

Fix: 2.50+
Fix from $1,950 2016-02-07
Gs1900 10hp Firmware HIGH 8.8
CVE-2015-5990

Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authenticatio…

Fix: 2.50+
Fix from $1,950 2015-12-31
Gs1900 10hp Firmware CRITICAL 9.8
CVE-2015-5989

Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain adminis…

Fix: 2.50+
Fix from $2,300 2015-12-31
Gs1900 10hp Firmware CRITICAL 9.8
CVE-2015-5988

The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administ…

Fix: 2.50+
Fix from $2,300 2015-12-31
Gs1900 10hp Firmware HIGH 8.6
CVE-2015-5987

Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easi…

Fix: 2.50+
Fix from $1,950 2015-12-31
Nbg 418n Firmware HIGH 8.0
CVE-2015-7284

Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authenti…

Mitigation only
Fix from $1,950 2015-12-31
Nbg 418n Firmware HIGH 8.1
CVE-2015-7283

The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which a…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware HIGH 8.0
CVE-2015-6020

ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware HIGH 8.5
CVE-2015-6019

The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote a…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware CRITICAL 9.8
CVE-2015-6018EPSS 21%

The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary com…

No fix yet
Fix from $2,300 2015-12-31
P 660hw T1 V2 Firmware MEDIUM 6.1
CVE-2015-6017

Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote atta…

Mitigation only
Fix from $1,600 2015-12-31
Nbg 418n CRITICAL 9.8
CVE-2015-6016EPSS 6%

ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default passw…

Mitigation only
Fix from $2,300 2015-12-31
Sbg3300 N Firmware MEDIUM 5.0
CVE-2014-7278

The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (…

Fix: after 1.00
Fix from $1,600 2014-10-04