Show filters
303 Total Results
Displaying 281-290 of 303
Sort by:
Attacker Value
Unknown

CVE-2008-1254

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1259

Disclosure Date: March 10, 2008 (last updated October 04, 2023)
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
0
Attacker Value
Unknown

CVE-2007-4319

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE.
0
Attacker Value
Unknown

CVE-2007-4316

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions.
0
Attacker Value
Unknown

CVE-2007-4318

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.
0
Attacker Value
Unknown

CVE-2007-4317

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allow remote attackers to perform certain actions as administrators, as demonstrated by a request to Forms/General_1 with the (1) sysSystemName and (2) sysDomainName parameters.
0
Attacker Value
Unknown

CVE-2007-1586

Disclosure Date: March 21, 2007 (last updated October 04, 2023)
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.
0
Attacker Value
Unknown

CVE-2006-3929

Disclosure Date: July 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.
0
Attacker Value
Unknown

CVE-2006-2562

Disclosure Date: May 24, 2006 (last updated October 04, 2023)
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
0
Attacker Value
Unknown

CVE-2006-0302

Disclosure Date: January 19, 2006 (last updated February 22, 2025)
ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.
0