Show filters
303 Total Results
Displaying 151-160 of 303
Sort by:
Attacker Value
Unknown
CVE-2021-35031
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
0
Attacker Value
Unknown
CVE-2021-35033
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
0
Attacker Value
Unknown
CVE-2021-35027
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
0
Attacker Value
Unknown
CVE-2021-35028
Disclosure Date: September 29, 2021 (last updated February 23, 2025)
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
0
Attacker Value
Unknown
CVE-2021-35030
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.
0
Attacker Value
Unknown
CVE-2021-35029
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
0
Attacker Value
Unknown
CVE-2020-28899
Disclosure Date: March 16, 2021 (last updated February 22, 2025)
The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via crafted JSON action data to /cgi-bin/gui.cgi) to use all features provided by the router. Examples: change the router password, retrieve the Wi-Fi passphrase, send an SMS message, or modify the IP forwarding to access the internal network.
0
Attacker Value
Unknown
CVE-2021-3297
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
0
Attacker Value
Unknown
CVE-2020-29299
Disclosure Date: December 27, 2020 (last updated February 22, 2025)
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.
0
Attacker Value
Unknown
CVE-2020-20183
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.
0