Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2020-15312
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15313
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15314
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
Cloudcnm Secumanager
No fix yet
HIGH 7.5
CVE-2020-15335
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Cloudcnm Secumanager
Mitigation only
HIGH 7.5
CVE-2020-15336
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Cloudcnm Secumanager
Mitigation only
CRITICAL 9.8
CVE-2020-15348
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python c…
Cloud Cnm Secumanager
No fix yet
HIGH 8.6
CVE-2020-14461EPSS 10%
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
Wap6806 Firmware
No fix yet
MEDIUM 5.4
CVE-2019-13495
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitra…
Xgs2210 52hp Firmware
No fix yet
CRITICAL 9.8
CVE-2020-9054 KEVEPSS 100%
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, whi…
Nas326 Firmware
4.35 / 5.21+
CRITICAL 9.8
CVE-2019-15800
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec()…
Gs1900 8 Firmware
2.50+
CRITICAL 9.1
CVE-2019-15803
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented fun…
Gs1900 8 Firmware
2.50+
HIGH 8.8
CVE-2019-15799
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, w…
Gs1900 8 Firmware
2.50+
HIGH 7.5
CVE-2019-15801
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to…
Gs1900 8 Firmware
2.50+
HIGH 7.5
CVE-2019-15804
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionali…
Gs1900 8 Firmware
2.50+
MEDIUM 5.9
CVE-2019-15802
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry…
Gs1900 8 Firmware
2.50+
MEDIUM 6.5
CVE-2019-15815
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized us…
2.00\(abbx.3\)
Patch available
CRITICAL 9.4
CVE-2019-17354
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure…
Nbg 418n V2 Firmware
Mitigation only
MEDIUM 6.1
CVE-2019-12581EPSS 6%
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows r…
Uag2100 Firmware
after 4.30
CRITICAL 9.1
CVE-2019-12583EPSS 44%
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts…
Uag2100 Firmware
after 4.33
CRITICAL 9.8
CVE-2019-6725
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm…
P 660hn T1 Firmware
Mitigation only
MEDIUM 6.1
CVE-2019-9955EPSS 21%
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 1…
Atp200 Firmware
Patch available
HIGH 8.8
CVE-2019-10630
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
Nas326 Firmware
after 5.21
HIGH 8.8
CVE-2019-10631
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary …
Nas326 Firmware
after 5.21
HIGH 8.8
CVE-2019-10633
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker t…
Nas326 Firmware
after 5.21
MEDIUM 6.5
CVE-2019-10632
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to chang…
Nas326 Firmware
after 5.21
MEDIUM 5.4
CVE-2019-10634
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via th…
Nas326 Firmware
after 5.21
HIGH 8.8
CVE-2019-7391EPSS 14%
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
Dsl 491hnu B10b Firmware
No fix yet
HIGH 8.8
CVE-2019-6710
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
Nbg 418n Firmware
No fix yet
HIGH 8.8
CVE-2018-14892
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changi…
Nsa325 V2 Firmware
No fix yet
HIGH 8.8
CVE-2018-14893
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web applic…
Nsa325 V2 Firmware
No fix yet