Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-4029 A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a… Nbg6816 Firmware 1.00+ Fix from $1,9502022-02-24 HIGH 8.8 CVE-2021-4030 A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands… Nbg6816 Firmware 1.00+ Fix from $1,9502022-02-24 CRITICAL 9.1 CVE-2021-35034 An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device … Nbg6604 Firmware 1.00+ Fix from $2,3002021-12-29 MEDIUM 6.5 CVE-2021-35035 A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensi… Nbg6604 Firmware 1.00+ Fix from $1,6002021-12-29 HIGH 8.0 CVE-2021-35031 A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authen… Gs1900 8 Firmware 2.70+ Fix from $1,9502021-12-28 HIGH 7.8 CVE-2021-35032 A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS c… Gs1900 8 Firmware 2.70+ Fix from $1,9502021-12-28 HIGH 7.8 CVE-2021-35033 A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could… Nbg6818 Firmware 1.00 / 2.20+ Fix from $1,9502021-11-23 HIGH 7.8 CVE-2021-35028 A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arb… Zywall Vpn2s Firmware Patch available Fix from $1,9502021-09-29 HIGH 7.5 CVE-2021-35027 A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensit… Zywall Vpn2s Firmware Patch available Fix from $1,9502021-09-29 CRITICAL 9.8 CVE-2021-35029 An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG … Usg1900 Firmware after 4.64 Fix from $2,3002021-07-02 CRITICAL 9.1 CVE-2020-28899 The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via … Lte4506 M606 Firmware Mitigation only Fix from $2,3002021-03-16 HIGH 7.8 CVE-2021-3297EPSS 21% On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. Nbg2105 Firmware No fix yet Fix from $1,9502021-01-26 HIGH 7.2 CVE-2020-29299 Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-pr… Vpn Orchestrator 1.33 / 4.39+ Fix from $1,9502020-12-27 CRITICAL 9.8 CVE-2020-29583 KEVEPSS 90% Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can … Usg20 Vpn Firmware Mitigation only Fix from $2,3002020-12-22 HIGH 7.5 CVE-2020-20183 Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil… P1302 T10 V3 Firmware Mitigation only Fix from $1,9502020-12-14 CRITICAL 9.8 CVE-2020-25014 A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows r… Zld after 6.10 Fix from $2,3002020-11-27 CRITICAL 9.8 CVE-2020-24355 Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows … Vmg5313 B30b Firmware after 5.13 Fix from $2,3002020-09-02 HIGH 8.8 CVE-2020-24354 Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection. Vmg5313 B30b Firmware after 5.13 Fix from $1,9502020-08-31 HIGH 8.8 CVE-2020-13364 A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3… Nas326 Firmware Mitigation only Fix from $1,9502020-08-06 HIGH 8.8 CVE-2020-13365 Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can … Nas326 Firmware Mitigation only Fix from $1,9502020-08-06 CRITICAL 9.8 CVE-2020-15320 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account. Cloudcnm Secumanager No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-15321 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account. Cloudcnm Secumanager No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-15322 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account. Cloudcnm Secumanager No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-15323 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. Cloudcnm Secumanager No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-15324 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials. Cloud Cnm Secumanager No fix yet Fix from $2,3002020-06-29 MEDIUM 5.9 CVE-2020-15315 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15316 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15317 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15318 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15319 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29