Vulnerabilities > Zyxel > Vmg3312 B10B Firmware

DATE CVE VULNERABILITY TITLE RISK
2018-10-29 CVE-2018-18754 Insufficiently Protected Credentials vulnerability in Zyxel Vmg3312-B10B Firmware 1.00(Aapp.7)
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
network
low complexity
zyxel CWE-522
critical
9.8
2018-08-26 CVE-2018-15602 Cross-site Scripting vulnerability in Zyxel Vmg3312 B10B Firmware
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
network
low complexity
zyxel CWE-79
6.1