Zyxel
zyxel
329 CVEs • 885 products
Products (885)
Click to collapseToggle
Products (885)
Click to collapse
CVEs (329)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerabilit...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and an...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 21, 2024 May 2, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vul...Show more |
2Billion Zyxel35200w T Firmware P660hn T1a V1 FirmwareP660hn T1a V2 FirmwareNov 5, 2025 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenti...Show more |
1Zyxel 21Atp200 Firmware Atp500 FirmwareAtp800 Firmware+18 moreJun 17, 2026 Apr 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page i...Show more |
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields. |
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs. |
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files. |
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests. |
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device. |
1Zyxel 2Dsl 491hnu B10b Firmware Dsl 491hnu B1b V2 FirmwareJun 17, 2026 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. |
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. |
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API. |
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms. |
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd. |
1Zyxel 1Zywall Usg 100 Firmware Nov 21, 2024 Nov 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored X...Show more |
1Zyxel 1Vmg3312 B10b Firmware Nov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. |
1Zyxel 1Vmg3312 B10b Firmware Nov 21, 2024 Aug 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter. |
1Zyxel 17Usg 1100 Firmware Usg 110 FirmwareUsg 1900 Firmware+14 moreJun 17, 2026 Aug 15, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections. |