Vulnerability index

Browse CVEs

275 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2020-15312 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15313 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15314 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 HIGH 7.5 CVE-2020-15335 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests. Cloudcnm Secumanager Mitigation only Fix from $1,9502020-06-26 HIGH 7.5 CVE-2020-15336 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests. Cloudcnm Secumanager Mitigation only Fix from $1,9502020-06-26 CRITICAL 9.8 CVE-2020-15348 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c… Cloud Cnm Secumanager No fix yet Fix from $2,3002020-06-26 HIGH 8.6 CVE-2020-14461EPSS 10% Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. Wap6806 Firmware No fix yet Fix from $1,9502020-06-22 MEDIUM 5.4 CVE-2019-13495 In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitra… Xgs2210 52hp Firmware No fix yet Fix from $1,6002020-03-31 CRITICAL 9.8 CVE-2020-9054 KEVEPSS 100% Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi… Nas326 Firmware 4.35 / 5.21+ Fix from $2,3002020-03-04 CRITICAL 9.8 CVE-2019-15800 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()… Gs1900 8 Firmware 2.50+ Fix from $2,3002019-11-14 CRITICAL 9.1 CVE-2019-15803 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented fun… Gs1900 8 Firmware 2.50+ Fix from $2,3002019-11-14 HIGH 8.8 CVE-2019-15799 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w… Gs1900 8 Firmware 2.50+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2019-15801 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to… Gs1900 8 Firmware 2.50+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2019-15804 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionali… Gs1900 8 Firmware 2.50+ Fix from $1,9502019-11-14 MEDIUM 5.9 CVE-2019-15802 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry… Gs1900 8 Firmware 2.50+ Fix from $1,6002019-11-14 MEDIUM 6.5 CVE-2019-15815 ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized us… 2.00\(abbx.3\) Patch available Fix from $1,6002019-11-12 CRITICAL 9.4 CVE-2019-17354 wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure… Nbg 418n V2 Firmware Mitigation only Fix from $2,3002019-10-09 MEDIUM 6.1 CVE-2019-12581EPSS 6% A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows r… Uag2100 Firmware after 4.30 Fix from $1,6002019-06-27 CRITICAL 9.1 CVE-2019-12583EPSS 44% Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts… Uag2100 Firmware after 4.33 Fix from $2,3002019-06-27 CRITICAL 9.8 CVE-2019-6725 The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm… P 660hn T1 Firmware Mitigation only Fix from $2,3002019-05-31 MEDIUM 6.1 CVE-2019-9955EPSS 21% On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 1… Atp200 Firmware Patch available Fix from $1,6002019-04-22 HIGH 8.8 CVE-2019-10630 A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device. Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-10631 Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary … Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-10633 An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t… Nas326 Firmware after 5.21 Fix from $1,9502019-04-09 MEDIUM 6.5 CVE-2019-10632 A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to chang… Nas326 Firmware after 5.21 Fix from $1,6002019-04-09 MEDIUM 5.4 CVE-2019-10634 An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via th… Nas326 Firmware after 5.21 Fix from $1,6002019-04-09 HIGH 8.8 CVE-2019-7391EPSS 14% ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. Dsl 491hnu B10b Firmware No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2019-6710 Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. Nbg 418n Firmware No fix yet Fix from $1,9502019-03-07 HIGH 8.8 CVE-2018-14892 Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi… Nsa325 V2 Firmware No fix yet Fix from $1,9502018-11-27 HIGH 8.8 CVE-2018-14893 A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic… Nsa325 V2 Firmware No fix yet Fix from $1,9502018-11-27