Zyxel
zyxel
326 CVEs • 881 products
Products (881)
Click to collapseToggle
Products (881)
Click to collapse
CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages. |
1Zyxel 2Access Points Firmware ZldDec 12, 2024 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted...Show more |
1Zyxel 1Vmg5313 B30b Firmware Nov 21, 2024 Sep 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. T...Show more |
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection. |
1Zyxel 4Nas326 Firmware Nas520 FirmwareNas540 Firmware+1 moreNov 21, 2024 Aug 6, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)...Show more |
1Zyxel 4Nas326 Firmware Nas520 FirmwareNas540 Firmware+1 moreNov 21, 2024 Aug 6, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and...Show more |
1Zyxel 1Cloud Cnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account. |
1Zyxel 1Cloudcnm Secumanager Nov 21, 2024 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. |
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests. |