Vulnerabilities > Zyxel > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-10-09 CVE-2019-17354 Missing Authentication for Critical Function vulnerability in Zyxel Nbg-418N V2 Firmware 1.00(Aarp.9)C0
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.
network
low complexity
zyxel CWE-306
critical
9.4
2019-06-27 CVE-2019-12583 Forced Browsing vulnerability in Zyxel products
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator.
network
low complexity
zyxel CWE-425
critical
9.1
2019-05-31 CVE-2019-6725 Use of Hard-coded Credentials vulnerability in Zyxel P-660Hn-T1 Firmware 2.00(Aakk.3)
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices.
network
low complexity
zyxel CWE-798
critical
9.8
2019-05-02 CVE-2017-18371 Use of Hard-coded Credentials vulnerability in multiple products
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.
network
low complexity
billion zyxel CWE-798
critical
9.8
2019-05-02 CVE-2017-18368 OS Command Injection vulnerability in multiple products
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user.
network
low complexity
billion zyxel CWE-78
critical
9.8
2018-10-29 CVE-2018-18754 Insufficiently Protected Credentials vulnerability in Zyxel Vmg3312-B10B Firmware 1.00(Aapp.7)
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
network
low complexity
zyxel CWE-522
critical
9.8
2018-02-21 CVE-2018-1164 Incorrect Permission Assignment for Critical Resource vulnerability in Zyxel P-870H-51 Firmware 1.00(Awg.3)D5
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5.
network
low complexity
zyxel CWE-732
critical
9.8
2017-10-10 CVE-2017-15226 OS Command Injection vulnerability in Zyxel Nbg6716 Firmware 1.00(Aakg.9)C0
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.
network
low complexity
zyxel CWE-78
critical
9.8
2017-06-20 CVE-2017-3216 Missing Authentication for Critical Function vulnerability in multiple products
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
network
low complexity
greenpacket huawei mada zte zyxel CWE-306
critical
9.8
2017-04-19 CVE-2017-7964 Insecure Default Initialization of Resource vulnerability in Zyxel Wre6505 Firmware V1.00(Aaqb.3)C0
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.
network
low complexity
zyxel CWE-1188
critical
10.0