← Back

Zyxel

zyxel

329 CVEs • 885 products

Products (885)

Click to collapse
Toggle
Zld
zld
Zynos
zynos

CVEs (329)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Samsung
SunZyxel+1 more
4Gs1900 10hp Firmware
Keymouse FirmwareOpensolaris+1 more
May 6, 2026
Mar 3, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileg...Show more
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.Show less
4Samsung
SunZyxel+1 more
4Gs1900 10hp Firmware
Keymouse FirmwareOpensolaris+1 more
May 6, 2026
Feb 9, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express...Show more
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.Show less
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Feb 9, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy110...Show more
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.Show less
2Zyxel
Zzinc
2Gs1900 10hp Firmware
Keymouse Firmware
May 6, 2026
Feb 7, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bu...Show more
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.Show less
5Cisco
SamsungSun+2 more
5Gs1900 10hp Firmware
Keymouse FirmwareNx Os+2 more
May 6, 2026
Feb 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote a...Show more
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.Show less
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Feb 7, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of service (device reload) via an IPv4 ICMP packet with the IP Record Route o...Show more
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of service (device reload) via an IPv4 ICMP packet with the IP Record Route option, aka Bug ID CSCuq57512.Show less
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success...Show more
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.Show less
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
1Zyxel
2Nbg 418n
Nbg 418n Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.0 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.
1Zyxel
1Nbg 418n Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveragin...Show more
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.Show less
1Zyxel
1Pmg5318 B20a Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.0 HIGH· v3
8.3 HIGH· v2
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the user account.
1Zyxel
1Pmg5318 B20a Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
8.5 HIGH· v3
5.0 MEDIUM· v2
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unatte...Show more
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.Show less
1Zyxel
1Pmg5318 B20a Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
1Zyxel
1P 660hw T1 V2 Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.Show less
1Zyxel
3Nbg 418n
Pmg5318 B20a FirmwareZynos Firmware
May 6, 2026
Dec 31, 2015
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obt...Show more
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.Show less
1Zyxel
2Sbg3300 N
Sbg3300 N Firmware
May 6, 2026
Oct 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified...Show more
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified "welcome message" form data that is improperly handled during use for the loginMsg variable's value, a different vulnerability than CVE-2014-7277.Show less
1Zyxel
2Sbg3300 N
Sbg3300 N Firmware
May 6, 2026
Oct 4, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "w...Show more
Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "welcome message" form data that is improperly handled during rendering of the loginMessage list item, a different vulnerability than CVE-2014-7278.Show less
1Zyxel
1P 660hw
May 6, 2026
Jun 16, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.Show less