Show filters
303 Total Results
Displaying 11-20 of 303
Sort by:
Attacker Value
Unknown

CVE-2024-40890

Disclosure Date: February 04, 2025 (last updated February 13, 2025)
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
Attacker Value
Unknown

CVE-2024-12398

Disclosure Date: January 14, 2025 (last updated January 22, 2025)
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
Attacker Value
Unknown

CVE-2024-9200

Disclosure Date: December 03, 2024 (last updated January 22, 2025)
A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
0
Attacker Value
Unknown

CVE-2024-9197

Disclosure Date: December 03, 2024 (last updated January 22, 2025)
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.
Attacker Value
Unknown

CVE-2024-8748

Disclosure Date: December 03, 2024 (last updated January 22, 2025)
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.
0
Attacker Value
Unknown

CVE-2024-11667

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.
Attacker Value
Unknown

CVE-2024-11494

Disclosure Date: November 20, 2024 (last updated January 05, 2025)
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device information via a crafted HTTP HEAD method.
Attacker Value
Unknown

CVE-2024-8882

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.
Attacker Value
Unknown

CVE-2024-8881

Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2024-9677

Disclosure Date: October 22, 2024 (last updated December 21, 2024)
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.