Vulnerabilities > Zyxel > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-29 CVE-2020-15313 Use of Hard-coded Credentials vulnerability in Zyxel Cloudcnm Secumanager 3.1.0/3.1.1
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
network
high complexity
zyxel CWE-798
5.9
2020-06-29 CVE-2020-15312 Use of Hard-coded Credentials vulnerability in Zyxel Cloudcnm Secumanager 3.1.0/3.1.1
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
network
high complexity
zyxel CWE-798
5.9
2020-03-31 CVE-2019-13495 Cross-site Scripting vulnerability in Zyxel Xgs2210-52Hp Firmware 4.50
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.
network
low complexity
zyxel CWE-79
5.4
2019-11-14 CVE-2019-15802 Use of Hard-coded Credentials vulnerability in Zyxel products
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0.
network
high complexity
zyxel CWE-798
5.9
2019-11-12 CVE-2019-15815 Authorization Bypass Through User-Controlled Key vulnerability in Zyxel 2.00(Abbx.3)
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized user to access certain pages that require admin privileges.
network
low complexity
zyxel CWE-639
6.5
2019-06-27 CVE-2019-12581 Cross-site Scripting vulnerability in Zyxel products
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
network
low complexity
zyxel CWE-79
6.1
2019-04-22 CVE-2019-9955 Cross-site Scripting vulnerability in Zyxel products
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
network
low complexity
zyxel CWE-79
6.1
2019-04-09 CVE-2019-10634 Cross-site Scripting vulnerability in Zyxel Nas326 Firmware 5.21
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
network
low complexity
zyxel CWE-79
5.4
2019-04-09 CVE-2019-10632 Path Traversal vulnerability in Zyxel Nas326 Firmware 5.21
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
network
low complexity
zyxel CWE-22
6.5
2018-08-26 CVE-2018-15602 Cross-site Scripting vulnerability in Zyxel Vmg3312 B10B Firmware
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
network
low complexity
zyxel CWE-79
6.1