Zyxel
zyxel
326 CVEs • 881 products
Products (881)
Click to collapseToggle
Products (881)
Click to collapse
CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests. |
1Zyxel 1Cloud Cnm Secumanager Nov 21, 2024 Jun 26, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code. |
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI. |
21Asus BroadcomCanon+18 more2175020 Z4a69a 5030 M2u92b5030 Z4a70a+214 moreNov 21, 2024 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more |
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field. |
1Zyxel 27Atp100 Firmware Atp200 FirmwareAtp500 Firmware+24 moreNov 10, 2025 Mar 4, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary co...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionality is triggered. Specifically, a menu can be triggered by sending the S...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The paramete...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recover...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclic...Show more |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreNov 21, 2024 Nov 14, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged...Show more |
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized user to access certain pages that require admin privileges. |
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker...Show more |
1Zyxel 9Uag2100 Firmware Uag4100 FirmwareUag5100 Firmware+6 moreNov 21, 2024 Jun 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg...Show more |
1Zyxel 14Uag2100 Firmware Uag4100 FirmwareUag5100 Firmware+11 moreNov 21, 2024 Jun 27, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthor...Show more |
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerabilit...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and an...Show more |