Vulnerabilities > Zyxel > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-26413 OS Command Injection vulnerability in Zyxel products
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
low complexity
zyxel CWE-78
8.0
2022-04-11 CVE-2022-0556 Incorrect Permission Assignment for Critical Resource vulnerability in Zyxel AP Configurator 1.1.4
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
local
low complexity
zyxel CWE-732
7.8
2022-02-24 CVE-2021-4029 OS Command Injection vulnerability in Zyxel Nbg6816 Firmware and Nbg6817 Firmware
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.
low complexity
zyxel CWE-78
8.8
2022-02-24 CVE-2021-4030 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel Nbg6816 Firmware and Nbg6817 Firmware
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.
network
low complexity
zyxel CWE-352
8.8
2021-12-28 CVE-2021-35031 OS Command Injection vulnerability in Zyxel products
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
low complexity
zyxel CWE-78
8.0
2021-12-28 CVE-2021-35032 OS Command Injection vulnerability in Zyxel products
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
local
low complexity
zyxel CWE-78
7.8
2021-11-23 CVE-2021-35033 Improper Authentication vulnerability in Zyxel products
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
local
low complexity
zyxel CWE-287
7.8
2021-09-29 CVE-2021-35027 Path Traversal vulnerability in Zyxel Zywall Vpn2S Firmware 1.12(Abln.0)C0
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information.
network
low complexity
zyxel CWE-22
7.5
2021-09-29 CVE-2021-35028 OS Command Injection vulnerability in Zyxel Zywall Vpn2S Firmware 1.12(Abln.0)C0
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
local
low complexity
zyxel CWE-78
7.8
2021-01-26 CVE-2021-3297 Improper Authentication vulnerability in Zyxel Nbg2105 Firmware V1.00(Aagu.2)C0
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
local
low complexity
zyxel CWE-287
7.8