Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-28769EPSS 5% The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1… Dx5401 B0 Firmware 5.17+ Fix from $2,3002023-04-27 HIGH 7.5 CVE-2023-28770EPSS 58% The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(AB… Dx5401 B0 Firmware 5.17+ Fix from $1,9502023-04-27 CRITICAL 9.8 CVE-2023-28771 KEVEPSS 99% Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG F… Atp100 Firmware 5.35 / 5.36+ Fix from $2,3002023-04-25 HIGH 8.8 CVE-2023-27991 The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series f… Atp200 Firmware 5.36+ Fix from $1,9502023-04-24 MEDIUM 6.5 CVE-2023-22918 A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series … Atp200 Firmware 5.36+ Fix from $1,6002023-04-24 HIGH 8.1 CVE-2023-22913 A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 throu… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 8.1 CVE-2023-22916 The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W)… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 7.5 CVE-2023-22915 A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) … Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 7.5 CVE-2023-22917 A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware ver… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 HIGH 7.2 CVE-2023-22914 A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series fi… Usg Flex 100 Firmware after 5.35 Fix from $1,9502023-04-24 CRITICAL 9.8 CVE-2023-22920 A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration… Lte3202 M437 Firmware Mitigation only Fix from $2,3002023-02-21 HIGH 7.2 CVE-2022-38547 A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPN series f… Atp100 Firmware after 5.32 Fix from $1,9502023-02-07 MEDIUM 6.1 CVE-2022-45441 A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store m… Nbg 418n Firmware after 1.00 Fix from $1,6002023-02-07 MEDIUM 6.5 CVE-2022-45439 A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauth… Ax7501 B0 Firmware 5.17+ Fix from $1,6002023-01-17 CRITICAL 9.8 CVE-2022-43389 A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthentica… Lte3202 M437 Firmware 1.00 / 1.15+ Fix from $2,3002023-01-11 HIGH 8.8 CVE-2022-43390 A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker t… Lte7480 M804 Firmware 1.00 / 1.15+ Fix from $1,9502023-01-11 HIGH 8.2 CVE-2022-43393 An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C… Gs1350 6hp Firmware 4.70+ Fix from $1,9502023-01-11 MEDIUM 6.5 CVE-2022-43391 A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authentic… Lte3301 Plus Firmware 1.00+ Fix from $1,6002023-01-11 MEDIUM 6.5 CVE-2022-43392 A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated … Lte3301 Plus Firmware 1.00+ Fix from $1,6002023-01-11 CRITICAL 9.8 CVE-2022-38546 A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access… Nbg7510 Firmware after 1.00 Fix from $2,3002022-12-21 MEDIUM 6.1 CVE-2022-40603 A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware ver… Atp800 Firmware after 5.31 Fix from $1,6002022-12-06 CRITICAL 9.8 CVE-2022-40602 A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-… Lte3301 M209 Firmware 1.00+ Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2020-15331 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 CRITICAL 9.8 CVE-2020-15332 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 CRITICAL 9.8 CVE-2020-15347 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. Cloudcnm Secumanager No fix yet Fix from $2,3002022-09-29 HIGH 7.5 CVE-2020-15327 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 HIGH 7.5 CVE-2020-15340 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 HIGH 7.5 CVE-2020-15341 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 MEDIUM 6.1 CVE-2020-15339 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15328 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29