Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2018-19326EPSS 10%
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
Vmg1312 B10d Firmware
5.13+
HIGH 8.8
CVE-2017-17550
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This…
Zywall Usg 100 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-18754
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
Vmg3312 B10b Firmware
Mitigation only
MEDIUM 6.1
CVE-2018-15602
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname para…
Vmg3312 B10b Firmware
Mitigation only
MEDIUM 5.9
CVE-2018-9129
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec base…
Zywall 110 Firmware
Patch available
MEDIUM 6.8
CVE-2018-9149
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device …
Ac3000 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-1164
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.…
P 870h 51 Firmware
Mitigation only
HIGH 7.5
CVE-2018-5330
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.
P 660hw V3 Firmware
No fix yet
HIGH 7.5
CVE-2017-17901
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
P 660hw Firmware
No fix yet
CRITICAL 9.8
CVE-2017-15226
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen ca…
Nbg6716 Firmware
No fix yet
MEDIUM 5.9
CVE-2015-7256
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, …
Nwa1100 N Firmware
Mitigation only
HIGH 8.8
CVE-2016-10401EPSS 12%
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account passwo…
Pk5001z Firmware
No fix yet
CRITICAL 10.0
CVE-2017-7964
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct D…
Wre6505 Firmware
Patch available
HIGH 8.8
CVE-2017-6884 KEVEPSS 38%
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the …
Emg2926 Firmware
Mitigation only
HIGH 7.5
CVE-2016-10227
Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4…
Usg50 Firmware
Patch available
HIGH 7.5
CVE-2015-6260
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause…
Gs1900 10hp Firmware
2.50+
MEDIUM 5.4
CVE-2016-1307
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it e…
Gs1900 10hp Firmware
2.50+
HIGH 7.5
CVE-2015-6398
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of ser…
Gs1900 10hp Firmware
2.50+
HIGH 8.8
CVE-2015-5990
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authenticatio…
Gs1900 10hp Firmware
2.50+
CRITICAL 9.8
CVE-2015-5989
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain adminis…
Gs1900 10hp Firmware
2.50+
CRITICAL 9.8
CVE-2015-5988
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administ…
Gs1900 10hp Firmware
2.50+
HIGH 8.6
CVE-2015-5987
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easi…
Gs1900 10hp Firmware
2.50+
HIGH 8.0
CVE-2015-7284
Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authenti…
Nbg 418n Firmware
Mitigation only
HIGH 8.1
CVE-2015-7283
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which a…
Nbg 418n Firmware
Mitigation only
HIGH 8.0
CVE-2015-6020
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the…
Pmg5318 B20a Firmware
Mitigation only
HIGH 8.5
CVE-2015-6019
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote a…
Pmg5318 B20a Firmware
Mitigation only
CRITICAL 9.8
CVE-2015-6018EPSS 21%
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary com…
Pmg5318 B20a Firmware
No fix yet
MEDIUM 6.1
CVE-2015-6017
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote atta…
P 660hw T1 V2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2015-6016EPSS 6%
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default passw…
Nbg 418n
Mitigation only
MEDIUM 5.0
CVE-2014-7278
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (…
Sbg3300 N Firmware
after 1.00