Vulnerabilities > Zyxel > High

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2024-40890 OS Command Injection vulnerability in Zyxel products
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request.
network
low complexity
zyxel CWE-78
8.8
2025-02-04 CVE-2024-40891 OS Command Injection vulnerability in Zyxel products
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet.
network
low complexity
zyxel CWE-78
8.8
2025-01-14 CVE-2024-12398 Unspecified vulnerability in Zyxel products
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S firmware versions through 6.70(ACGG.2) could allow an authenticated user with limited privileges to escalate their privileges to that of an administrator, enabling them to upload configuration files to a vulnerable device.
network
low complexity
zyxel
8.8
2024-10-22 CVE-2024-9677 Insufficiently Protected Credentials vulnerability in Zyxel UOS 1.20/1.21
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator.
local
low complexity
zyxel CWE-522
7.8
2024-09-03 CVE-2024-42057 OS Command Injection vulnerability in Zyxel ZLD
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device.
network
high complexity
zyxel CWE-78
8.1
2024-09-03 CVE-2024-42058 NULL Pointer Dereference vulnerability in Zyxel ZLD
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from V5.20 through V5.38 could allow an unauthenticated attacker to cause DoS conditions by sending crafted packets to a vulnerable device.
network
low complexity
zyxel CWE-476
7.5
2024-09-03 CVE-2024-42059 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware versions from V5.00 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted compressed language file via FTP.
network
low complexity
zyxel CWE-78
7.2
2024-09-03 CVE-2024-42060 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted internal user agreement file to the vulnerable device.
network
low complexity
zyxel CWE-78
7.2
2024-09-03 CVE-2024-5412 Classic Buffer Overflow vulnerability in Zyxel products
A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
network
low complexity
zyxel CWE-120
7.5
2024-09-03 CVE-2024-7203 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device by executing a crafted CLI command.
network
low complexity
zyxel CWE-78
7.2