Vulnerabilities > Zyxel > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-09 CVE-2019-10634 Cross-site Scripting vulnerability in Zyxel Nas326 Firmware 5.21
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
network
low complexity
zyxel CWE-79
5.4
2019-04-09 CVE-2019-10632 Path Traversal vulnerability in Zyxel Nas326 Firmware 5.21
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
network
low complexity
zyxel CWE-22
6.5
2018-08-26 CVE-2018-15602 Cross-site Scripting vulnerability in Zyxel Vmg3312 B10B Firmware
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
network
low complexity
zyxel CWE-79
6.1
2018-08-15 CVE-2018-9129 Unspecified vulnerability in Zyxel products
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
network
high complexity
zyxel
5.9
2018-04-01 CVE-2018-9149 Use of Hard-coded Credentials vulnerability in Zyxel Ac3000 Firmware
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART.
low complexity
zyxel CWE-798
6.8
2017-09-28 CVE-2015-7256 Cryptographic Issues vulnerability in Zyxel products
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.
network
high complexity
zyxel CWE-310
5.9
2016-04-06 CVE-2016-1346 Resource Management Errors vulnerability in multiple products
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
network
high complexity
dell netgear samsung zyxel zzinc CWE-399
5.9
2016-03-26 CVE-2016-1344 Resource Management Errors vulnerability in multiple products
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
network
high complexity
cisco samsung sun zyxel lenovo netgear zzinc CWE-399
5.9
2016-02-09 CVE-2016-1319 Information Exposure vulnerability in multiple products
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.
network
low complexity
sun samsung zyxel zzinc CWE-200
5.3
2016-02-09 CVE-2016-1317 Information Exposure vulnerability in Zyxel Gs1900-10Hp Firmware 2.40
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
network
low complexity
zyxel CWE-200
4.3