Zyxel
zyxel
326 CVEs • 881 products
Products (881)
Click to collapseToggle
Products (881)
Click to collapse
CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vul...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 5, 2025 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenti...Show more |
1Zyxel 21Atp200 Firmware Atp500 FirmwareAtp800 Firmware+18 moreNov 21, 2024 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page i...Show more |
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields. |
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs. |
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files. |
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests. |
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device. |
1Zyxel 2Dsl 491hnu B10b Firmware Dsl 491hnu B1b V2 FirmwareNov 21, 2024 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. |
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. |
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API. |
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms. |
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. |
1Zyxel 1Zywall Usg 100 Firmware Nov 21, 2024 Nov 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored X...Show more |
1Zyxel 1Vmg3312 B10b Firmware Nov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. |
1Zyxel 1Vmg3312 B10b Firmware Nov 21, 2024 Aug 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter. |
1Zyxel 17Usg 1100 Firmware Usg 110 FirmwareUsg 1900 Firmware+14 moreNov 21, 2024 Aug 15, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections. |
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234...Show more |
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The...Show more |
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets. |