← Back

Zyxel

zyxel

329 CVEs • 885 products

Products (885)

Click to collapse
Toggle
Zld
zld
Zynos
zynos

CVEs (329)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Billion
Zyxel
35200w T Firmware
P660hn T1a V1 FirmwareP660hn T1a V2 Firmware
Nov 21, 2024
May 2, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password...Show more
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.Show less
2Billion
Zyxel
35200w T Firmware
P660hn T1a V1 FirmwareP660hn T1a V2 Firmware
Nov 21, 2024
May 2, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerabilit...Show more
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.Show less
2Billion
Zyxel
35200w T Firmware
P660hn T1a V1 FirmwareP660hn T1a V2 Firmware
Nov 21, 2024
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and an...Show more
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.Show less
2Billion
Zyxel
35200w T Firmware
P660hn T1a V1 FirmwareP660hn T1a V2 Firmware
Nov 21, 2024
May 2, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vul...Show more
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371.Show less
2Billion
Zyxel
35200w T Firmware
P660hn T1a V1 FirmwareP660hn T1a V2 Firmware
Nov 5, 2025
May 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenti...Show more
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.Show less
1Zyxel
21Atp200 Firmware
Atp500 FirmwareAtp800 Firmware+18 more
Jun 17, 2026
Apr 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page i...Show more
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.Show less
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
1Zyxel
2Dsl 491hnu B10b Firmware
Dsl 491hnu B1b V2 Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
1Zyxel
1Nbg 418n Firmware
Jun 17, 2026
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
1Zyxel
1Nsa325 V2 Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API.
1Zyxel
1Nsa325 V2 Firmware
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.
1Zyxel
1Vmg1312 B10d Firmware
Nov 21, 2024
Nov 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
1Zyxel
1Zywall Usg 100 Firmware
Nov 21, 2024
Nov 10, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored X...Show more
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.Show less
1Zyxel
1Vmg3312 B10b Firmware
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
1Zyxel
1Vmg3312 B10b Firmware
Nov 21, 2024
Aug 26, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
1Zyxel
17Usg 1100 Firmware
Usg 110 FirmwareUsg 1900 Firmware+14 more
Jun 17, 2026
Aug 15, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.