Show filters
303 Total Results
Displaying 141-150 of 303
Sort by:
Attacker Value
Unknown

CVE-2022-26413

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
Attacker Value
Unknown

CVE-2022-0556

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
Attacker Value
Unknown

CVE-2021-46387

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.
Attacker Value
Unknown

CVE-2021-4039

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
Attacker Value
Unknown

CVE-2021-35036

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
Attacker Value
Unknown

CVE-2021-4030

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.
Attacker Value
Unknown

CVE-2021-4029

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.
Attacker Value
Unknown

CVE-2021-35035

Disclosure Date: December 29, 2021 (last updated February 23, 2025)
A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
Attacker Value
Unknown

CVE-2021-35034

Disclosure Date: December 29, 2021 (last updated February 23, 2025)
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.
Attacker Value
Unknown

CVE-2021-35032

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.