Vulnerabilities > Zyxel > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-15801 Use of Hard-coded Credentials vulnerability in Zyxel products
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0.
network
low complexity
zyxel CWE-798
7.5
2019-11-14 CVE-2019-15799 Improper Privilege Management vulnerability in Zyxel products
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0.
network
low complexity
zyxel CWE-269
8.8
2019-05-02 CVE-2017-18374 Use of Hard-coded Credentials vulnerability in multiple products
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true.
network
low complexity
billion zyxel CWE-798
8.8
2019-05-02 CVE-2017-18372 OS Command Injection vulnerability in multiple products
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user.
network
low complexity
billion zyxel CWE-78
8.8
2019-05-02 CVE-2017-18370 OS Command Injection vulnerability in multiple products
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user.
network
low complexity
billion zyxel CWE-78
8.8
2019-04-09 CVE-2019-10633 Code Injection vulnerability in Zyxel Nas326 Firmware 5.21
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
network
low complexity
zyxel CWE-94
8.8
2019-04-09 CVE-2019-10631 OS Command Injection vulnerability in Zyxel Nas326 Firmware 5.21
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
network
low complexity
zyxel CWE-78
8.8
2019-04-09 CVE-2019-10630 Insufficiently Protected Credentials vulnerability in Zyxel Nas326 Firmware 5.21
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
network
low complexity
zyxel CWE-522
8.8
2019-03-21 CVE-2019-7391 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel products
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
network
low complexity
zyxel CWE-352
8.8
2019-03-07 CVE-2019-6710 Cross-Site Request Forgery (CSRF) vulnerability in Zyxel Nbg-418N Firmware 1.00(Aaxm.6)C0
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
network
low complexity
zyxel CWE-352
8.8