Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-33477

Disclosure Date: June 06, 2023 (last updated October 08, 2023)
In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.
Attacker Value
Unknown

CVE-2020-29299

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.
Attacker Value
Unknown

CVE-2018-14942

Disclosure Date: August 05, 2018 (last updated November 27, 2024)
Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "POST /PY/EMULATION_GET_FILE" or "POST /PY/EMULATION_EXPORT" with FileName=../../../passwd in the POST data.
0
Attacker Value
Unknown

CVE-2018-14943

Disclosure Date: August 05, 2018 (last updated November 27, 2024)
Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for the config account.
0