Vulnerabilities > Zyxel > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-22 CVE-2020-14461 Path Traversal vulnerability in Zyxel Wap6806 Firmware 1.00(Abal.6)C0
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
network
low complexity
zyxel CWE-22
8.6
2020-06-08 CVE-2020-12695 Incorrect Default Permissions vulnerability in multiple products
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
7.5
2019-10-09 CVE-2019-17354 Missing Authentication for Critical Function vulnerability in Zyxel Nbg-418N V2 Firmware 1.00(Aarp.9)C0
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.
network
low complexity
zyxel CWE-306
7.5
2019-05-02 CVE-2017-18371 Use of Hard-coded Credentials vulnerability in multiple products
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.
network
low complexity
billion zyxel CWE-798
7.5
2019-03-21 CVE-2019-7391 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel products
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
network
low complexity
zyxel CWE-352
8.8
2018-04-01 CVE-2018-9149 Use of Hard-coded Credentials vulnerability in Zyxel Ac3000 Firmware
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART.
local
low complexity
zyxel CWE-798
7.2
2018-01-16 CVE-2018-5330 Unspecified vulnerability in Zyxel P-660Hw V3 Firmware
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.
network
low complexity
zyxel
7.8
2017-12-29 CVE-2017-17901 Resource Exhaustion vulnerability in Zyxel P-660Hw Firmware
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
network
low complexity
zyxel CWE-400
7.8
2017-10-10 CVE-2017-15226 OS Command Injection vulnerability in Zyxel Nbg6716 Firmware 1.00(Aakg.9)C0
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.
network
low complexity
zyxel CWE-78
7.5
2017-02-21 CVE-2016-10227 Resource Management Errors vulnerability in Zyxel Nwa3560-N Firmware and Usg50 Firmware
Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets.
network
low complexity
zyxel CWE-399
7.8