← Back

Uag2100 Firmware

uag2100_firmware

Vendor: Zyxel • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zyxel
9Uag2100 Firmware
Uag4100 FirmwareUag5100 Firmware+6 more
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg...Show more
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.Show less
1Zyxel
14Uag2100 Firmware
Uag4100 FirmwareUag5100 Firmware+11 more
Nov 21, 2024
Jun 27, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthor...Show more
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.Show less