Vulnerabilities > Zyxel > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-26413 OS Command Injection vulnerability in Zyxel products
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
low complexity
zyxel CWE-78
7.7
2022-04-11 CVE-2022-0556 Incorrect Permission Assignment for Critical Resource vulnerability in Zyxel AP Configurator 1.1.4
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.
local
low complexity
zyxel CWE-732
7.8
2022-03-28 CVE-2022-0342 Improper Authentication vulnerability in Zyxel products
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
network
low complexity
zyxel CWE-287
7.5
2022-02-24 CVE-2021-4029 OS Command Injection vulnerability in Zyxel Nbg6816 Firmware and Nbg6817 Firmware
A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.
low complexity
zyxel CWE-78
8.3
2021-12-28 CVE-2021-35031 OS Command Injection vulnerability in Zyxel products
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
low complexity
zyxel CWE-78
7.7
2021-12-28 CVE-2021-35032 OS Command Injection vulnerability in Zyxel products
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
local
low complexity
zyxel CWE-78
7.2
2021-11-23 CVE-2021-35033 Improper Authentication vulnerability in Zyxel products
A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable to connect the device, or if the remote assistance feature had been enabled by an authenticated user.
local
low complexity
zyxel CWE-287
7.8
2021-09-29 CVE-2021-35028 OS Command Injection vulnerability in Zyxel Zywall Vpn2S Firmware 1.12(Abln.0)C0
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
local
low complexity
zyxel CWE-78
7.2
2021-07-02 CVE-2021-35029 Improper Authentication vulnerability in Zyxel products
An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.
network
low complexity
zyxel CWE-287
7.5
2021-01-26 CVE-2021-3297 Improper Authentication vulnerability in Zyxel Nbg2105 Firmware V1.00(Aagu.2)C0
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
local
low complexity
zyxel CWE-287
7.2