Show filters
303 Total Results
Displaying 281-290 of 303
Sort by:
Attacker Value
Unknown
CVE-2008-1254
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-1259
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
0
Attacker Value
Unknown
CVE-2007-4319
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE.
0
Attacker Value
Unknown
CVE-2007-4316
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions.
0
Attacker Value
Unknown
CVE-2007-4318
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.
0
Attacker Value
Unknown
CVE-2007-4317
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allow remote attackers to perform certain actions as administrators, as demonstrated by a request to Forms/General_1 with the (1) sysSystemName and (2) sysDomainName parameters.
0
Attacker Value
Unknown
CVE-2007-1586
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.
0
Attacker Value
Unknown
CVE-2006-3929
Disclosure Date: July 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.
0
Attacker Value
Unknown
CVE-2006-2562
Disclosure Date: May 24, 2006 (last updated October 04, 2023)
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
0
Attacker Value
Unknown
CVE-2006-0302
Disclosure Date: January 19, 2006 (last updated February 22, 2025)
ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.
0