← Back

Zyxel

zyxel

329 CVEs • 885 products

Products (885)

Click to collapse
Toggle
Zld
zld
Zynos
zynos

CVEs (329)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zyxel
1Nbg2105 Firmware
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
1Zyxel
4Nsg Firmware
Usg Flex FirmwareVpn Orchestrator+1 more
Jun 17, 2026
Dec 27, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 wee...Show more
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.Show less
1Zyxel
30Atp100 Firmware
Atp100w FirmwareAtp200 Firmware+27 more
Jun 17, 2026
Dec 22, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by some...Show more
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.Show less
1Zyxel
1P1302 T10 V3 Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
1Zyxel
2Access Points Firmware
Zld
Jun 17, 2026
Nov 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted...Show more
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.Show less
1Zyxel
1Vmg5313 B30b Firmware
Jun 17, 2026
Sep 2, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. T...Show more
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.Show less
1Zyxel
1Vmg5313 B30b Firmware
Jun 17, 2026
Aug 31, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
1Zyxel
4Nas326 Firmware
Nas520 FirmwareNas540 Firmware+1 more
Jun 17, 2026
Aug 6, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)...Show more
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.Show less
1Zyxel
4Nas326 Firmware
Nas520 FirmwareNas540 Firmware+1 more
Jun 17, 2026
Aug 6, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and...Show more
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.Show less
1Zyxel
1Cloud Cnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.