Show filters
303 Total Results
Displaying 101-110 of 303
Sort by:
Attacker Value
Unknown
CVE-2022-45439
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the device by leveraging another known vulnerability.
0
Attacker Value
Unknown
CVE-2022-43393
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.
0
Attacker Value
Unknown
CVE-2022-43392
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.
0
Attacker Value
Unknown
CVE-2022-43391
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2022-43390
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2022-43389
Disclosure Date: January 11, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.
0
Attacker Value
Unknown
CVE-2022-38546
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unauthenticated attacker to access the DNS server when the device is switched to the AP mode.
0
Attacker Value
Unknown
CVE-2022-40603
Disclosure Date: December 06, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.
0
Attacker Value
Unknown
CVE-2022-40602
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.
0
Attacker Value
Unknown
CVE-2020-15325
Disclosure Date: September 29, 2022 (last updated February 24, 2025)
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
0