Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-33013

Disclosure Date: August 14, 2023 (last updated February 25, 2025)
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2023-22919

Disclosure Date: May 01, 2023 (last updated February 24, 2025)
The post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.
Attacker Value
Unknown

CVE-2021-35035

Disclosure Date: December 29, 2021 (last updated February 23, 2025)
A cleartext storage of sensitive information vulnerability in the Zyxel NBG6604 firmware could allow a remote, authenticated attacker to obtain sensitive information from the configuration file.
Attacker Value
Unknown

CVE-2021-35034

Disclosure Date: December 29, 2021 (last updated February 23, 2025)
An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.