ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige | 642r |
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige_681 | * |
| zyxel | prestige_1600 | * |
ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zywall10 | 3.24_wa2 |
| zyxel | zywall10 | 3.24_wa1 |
| zyxel | zywall10 | 3.20_wa1 |
| zyxel | zywall10 | 3.50_wa1 |
| zyxel | zywall10 | 3.24_wa0 |
| zyxel | zywall10 | 3.20_wa0 |
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige | 642r |
| zyxel | prestige | 310 |
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige | 642r |
| zyxel | prestige | 310 |
Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via a long password.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige | 650r_11 |
| zyxel | prestige | 650hw_31 |
ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | is.3 |
| zyxel | zynos | 3.40 |
| zyxel | zynos | is.5 |
| zyxel | prestige | 650hw_31 |
| zyxel | prestige | 645r_a1 |
| zyxel | prestige | 650h |
| zyxel | prestige | 650hw |
| zyxel | prestige | 650r |
Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | vt020225a |
| zyxel | prestige | 681 |
Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zywall10 | 3.24_wa2 |
| zyxel | zywall10 | 3.24_wa1 |
| zyxel | zywall10 | 3.20_wa1 |
| zyxel | zywall10 | 4.07 |
| zyxel | zywall10 | 3.50_wa1 |
| zyxel | zywall10 | 3.50_wa2 |
| zyxel | zywall10 | 3.24_wa0 |
| zyxel | zywall10 | 3.20_wa0 |
Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| netgear | rt311 | * |
| netgear | rt314 | * |
| zyxel | prestige | 314 |
| zyxel | prestige | 324 |
| zyxel | prestige | 310 |
ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige_650r-31 | 3.40_ko.1 |
Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p2000w_version_1_voip_wifi_phone | wj.00.10 |
| zyxel | prestige_2000w_v.1voip_wi-fi_phone | wj.00.10 |
Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or spoofing the hardcoded DNS servers. NOTE: it could be argued that this issue reflects an inherent limitation of DNS itself, so perhaps it should not be included in CVE.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige_2000w_v.1voip_wi-fi_phone | wj.00.10 |
ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p2000w_version_2_voip_wifi_phone | wv.00.02 |
ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-335wt_router | * |
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | prestige_660h-61 | firmware_3.40_pt.0_b32 |
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.62 |
| zyxel | zywall_2 | * |
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allow remote attackers to perform certain actions as administrators, as demonstrated by a request to Forms/General_1 with the (1) sysSystemName and (2) sysDomainName parameters.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.62 |
| zyxel | zywall_2 | * |
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to inject arbitrary web script or HTML via the sysSystemName parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.62 |
| zyxel | zywall_2 | * |
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.62 |
| zyxel | zywall_2 | * |
Cross-site scripting (XSS) vulnerability in the web management interface in the ZyXEL P-330W router allows remote attackers to inject arbitrary web script or HTML via the pingstr parameter and other unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-330w_router | * |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote router management via goform/formRmtMgt or (2) modify the administrator password via goform/formPasswordSetup.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-330w_router | * |
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zywall_1050_firmware | - |
Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw | * |
The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw | * |
The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw | * |
Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw_d1 | v2 |
| zyxel | p-660hw | _t1 |
| zyxel | p-660hw_t3 | - |
| zyxel | p-660hw_d1 | - |
| zyxel | p-660hw_d3 | - |
| zyxel | p-660hw_t3 | v2 |
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-2602hw-d1a | * |
Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-2602hw-d1a | * |
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware provides different responses to admin page requests depending on whether a user is logged in, which allows remote attackers to obtain current login status by requesting an arbitrary admin URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-2602hw-d1a | 3.40(ajz.1) |
ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to gain privileges by accessing administrative URIs, as demonstrated by rpSysAdmin.html.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), have (1) "user" as their default password for the "user" account and (2) "1234" as their default password for the "admin" account, which makes it easier for remote attackers to obtain access.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain ISP and Dynamic DNS credentials by sending a direct request for (1) WAN.html, (2) wzPPPOE.html, and (3) rpDyDNS.html, and then reading the HTML source.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has "public" as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
The default SNMP configuration on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has a Trusted Host value of 0.0.0.0, which allows remote attackers to send SNMP requests from any source IP address.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-916,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-662hw-d3_firmware | * |
| zyxel | p-660h-d3_firmware | * |
| zyxel | p-661hnu-f3_firmware | * |
| zyxel | p-660h-t1_firmware | * |
| zyxel | p-660hw_d3_firmware | 3.40(pe9) |
| zyxel | p-660h-63_firmware | * |
| zyxel | p-660hw_d1_firmware | 3.40(pe9) |
| zyxel | p-661hw-d1_firmware | 3.40(pe9) |
| zyxel | p-662h-61_firmware | * |
| zyxel | p-663hn-51_firmware | 3.40(pe9) |
| zyxel | p-661h_firmware | * |
| zyxel | p-660h-61_firmware | * |
| zyxel | p-660h-61_firmware | 3.40(pe9) |
| zyxel | p-660hw_d3_firmware | * |
| zyxel | p-661hnu-f3_firmware | 3.40(pe9) |
| zyxel | p-663hn-51_firmware | * |
| zyxel | p-660h-d1_firmware | * |
| zyxel | p-662hw-d1_firmware | 3.40(pe9) |
| zyxel | p-660hw_t3_firmware | 3.40(pe9) |
| zyxel | p-661hnu-f1_firmware | * |
| zyxel | p-662hw-d_firmware | * |
| zyxel | p-660hw_t3_firmware | * |
| zyxel | p-661hnu-f1_firmware | 3.40(pe9) |
| zyxel | p-660h-67_firmware | * |
| zyxel | p-660hn-51_firmware | * |
| zyxel | p-661h_firmware | 3.40(pe9) |
| zyxel | p-660h-63_firmware | 3.40(pe9) |
| zyxel | p-660h-d3_firmware | 3.40(pe9) |
| zyxel | p-660h-67_firmware | 3.40(pe9) |
| zyxel | p-660h-d1_firmware | 3.40(pe9) |
| zyxel | p-661hw-d1_firmware | * |
| zyxel | p-660h-t1_firmware | 3.40(pe9) |
| zyxel | p-660hw_d1_firmware | * |
| zyxel | p-662hw-d1_firmware | * |
| zyxel | p-660hn-51_firmware | 3.40(pe9) |
| zyxel | p-662h-61_firmware | 3.40(pe9) |
| zyxel | p-662hw-d3_firmware | 3.40(pe9) |
| zyxel | p-662hw-d_firmware | 3.40(pe9) |
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
ZyXEL Prestige routers have a minimum password length for the admin account that is too small, which makes it easier for remote attackers to guess passwords via brute force methods.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zynos | 3.40 |
| zyxel | prestige_661 | hw-d1 |
| zyxel | prestige_660 | h-d1 |
| zyxel | prestige_660 | h-d3 |
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zywall_100 | * |
Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the PortRule_Name parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | o2_dsl_router_classic | * |
The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-16,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| genmei_mori | pseudoics | 0.3 |
| zyxel | p-330w_router | * |
| genmei_mori | pseudoics | 0.1 |
| genmei_mori | pseudoics | 0.2 |
The web management interface on Zyxel P660 devices allows remote attackers to cause a denial of service (reboot) via a flood of TCP SYN packets.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw_d1 | - |
| zyxel | p-660h-t1 | v2 |
| zyxel | p-660hw_d3 | - |
| zyxel | p-660h-61 | - |
| zyxel | p-660h-d3 | - |
| zyxel | p-660h-63 | - |
| zyxel | p-660h-d1 | - |
| zyxel | p-660hw_d1 | v2 |
| zyxel | p-660hw | _t1 |
| zyxel | p-660h-t3 | v2 |
| zyxel | p-660hw_t3 | - |
| zyxel | p-660h-t1 | - |
| zyxel | p-660hw_t3 | v2 |
| zyxel | p-660h-67 | - |
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw_d1 | - |
| dlink | dsl-2640r | - |
| sitecom | wl-174 | - |
| tp-link | td-8816 | - |
| huawei | mt882 | - |
| allegrosoft | rompager | * |
| dlink | dsl-2641r | - |
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | n300_netusb_nbg-419n_firmware | 1.00(bfq_6)c0 |
| zyxel | n300_netusb_nbg-419n | - |
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an unspecified account, which allows remote attackers to obtain index.asp login access via an HTTP request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | n300_netusb_nbg-419n_firmware | 1.00(bfq_6)c0 |
| zyxel | n300_netusb_nbg-419n | - |
Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp attribute in a yweather:condition element in a forecastrss file that is processed by the checkWeather function; the (2) WeatherCity or (3) WeatherDegree variable to the detectWeather function; unspecified input to the (4) UpnpAddRunRLQoS, (5) UpnpDeleteRunRLQoS, or (6) UpnpDeletePortCheckType function; or (7) the SET COUNTRY udps command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | n300_netusb_nbg-419n_firmware | 1.00(bfq_6)c0 |
| zyxel | n300_netusb_nbg-419n | - |
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters in input to the (1) detectWeather, (2) set_language, (3) SystemCommand, or (4) NTPSyncWithHost function in management.c, or a (5) SET COUNTRY, (6) SET WLAN SSID, (7) SET WLAN CHANNEL, (8) SET WLAN STATUS, or (9) SET WLAN COUNTRY udps command.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | n300_netusb_nbg-419n_firmware | 1.00(bfq_6)c0 |
| zyxel | n300_netusb_nbg-419n | - |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw | _t1 |
Cross-site scripting (XSS) vulnerability in the login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified "welcome message" form data that is improperly handled during rendering of the loginMessage list item, a different vulnerability than CVE-2014-7278.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | sbg3300-n | - |
| zyxel | sbg3300-n_firmware | * |
The login page on the ZyXEL SBG-3300 Security Gateway with firmware 1.00(AADY.4)C0 and earlier allows remote attackers to cause a denial of service (persistent web-interface outage) via JavaScript code within unspecified "welcome message" form data that is improperly handled during use for the loginMsg variable's value, a different vulnerability than CVE-2014-7277.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | sbg3300-n | - |
| zyxel | sbg3300-n_firmware | * |
Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | unified_computing_system | 2.1_3d |
| cisco | unified_computing_system | 1.4_4g |
| cisco | unified_computing_system | 1.4_4k |
| cisco | unified_computing_system | 2.1_2c |
| cisco | unified_computing_system | 1.4_4l |
| cisco | unified_computing_system | 1.4_4f |
| cisco | unified_computing_system | 2.0_4a |
| cisco | unified_computing_system | 2.0_4b |
| cisco | unified_computing_system | 2.0_1t |
| cisco | unified_computing_system | 1.6_base |
| cisco | nx-os | base |
| cisco | unified_computing_system | 2.0_5d |
| cisco | unified_computing_system | 2.0_1s |
| zyxel | gs1900-10hp_firmware | * |
| cisco | unified_computing_system | 2.0_5b |
| cisco | unified_computing_system | 1.4_3m |
| cisco | unified_computing_system | 2.0_1w |
| cisco | unified_computing_system | 2.2_1b |
| cisco | unified_computing_system | 2.0_4d |
| cisco | unified_computing_system | 1.4_4i |
| cisco | unified_computing_system | 1.4_3y |
| cisco | unified_computing_system | 2.0_5f |
| cisco | unified_computing_system | 2.0_5a |
| cisco | unified_computing_system | 2.1_1e |
| cisco | unified_computing_system | 2.1_1b |
| cisco | unified_computing_system | 2.0_2q |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| cisco | unified_computing_system | 2.2_2e |
| zzinc | keymouse_firmware | 3.08 |
| cisco | unified_computing_system | 2.0_3b |
| cisco | unified_computing_system | 2.0_3a |
| cisco | unified_computing_system | 2.0_3c |
| cisco | unified_computing_system | 1.5_base |
| cisco | unified_computing_system | 2.2_1e |
| cisco | unified_computing_system | 2.1_3b |
| cisco | unified_computing_system | 2.1_1d |
| cisco | unified_computing_system | 2.0_1q |
| cisco | unified_computing_system | 2.1_1f |
| cisco | unified_computing_system | 1.4_3i |
| netgear | jr6150_firmware | * |
| cisco | unified_computing_system | 2.2_2d |
| cisco | unified_computing_system | 1.4_4j |
| cisco | unified_computing_system | 2.1_2d |
| cisco | unified_computing_system | 2.1_2a |
| cisco | unified_computing_system | 2.0_5e |
| cisco | unified_computing_system | 1.4_3l |
| cisco | unified_computing_system | 1.4_1i |
| cisco | unified_computing_system | 1.4_1j |
| cisco | unified_computing_system | 2.1_3c |
| cisco | unified_computing_system | 1.4_3s |
| cisco | unified_computing_system | 2.0_1x |
| cisco | unified_computing_system | 2.0_5c |
| cisco | unified_computing_system | 2.0_2m |
| cisco | unified_computing_system | 2.1_3f |
| cisco | unified_computing_system | 1.4_3u |
| cisco | unified_computing_system | 1.4_1m |
| cisco | unified_computing_system | 2.2_2c |
| cisco | unified_computing_system | 2.1_3e |
| cisco | unified_computing_system | 2.1_3a |
| sun | opensolaris | snv_124 |
| cisco | unified_computing_system | 2.2_1d |
| cisco | unified_computing_system | 2.1_1a |
| cisco | unified_computing_system | 1.4_3q |
| cisco | unified_computing_system | 2.2_1c |
| cisco | unified_computing_system | 2.0_2r |
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0), PMG5318-B20A devices with firmware 1.00AANC0b5, and NBG-418N devices have a default password of 1234 for the admin account, which allows remote attackers to obtain administrative access via unspecified vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg-418n | - |
| zyxel | zynos_firmware | 3.40(axh.0) |
| zyxel | pmg5318-b20a_firmware | v100aanc0b5 |
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw-t1_v2_firmware | 3.40(axh.0) |
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | pmg5318-b20a_firmware | * |
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | pmg5318-b20a_firmware | v100aanc0b5 |
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the user account.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | pmg5318-b20a_firmware | v100aanc0b5 |
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zzinc | keymouse_firmware | 3.08 |
| netgear | jr6150_firmware | * |
| zyxel | gs1900-10hp_firmware | * |
| dell | emc_powerscale_onefs | 8.2.2 |
Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | opensolaris | snv_124 |
| zzinc | keymouse_firmware | 3.08 |
| zyxel | gs1900-10hp_firmware | * |
Cisco Nexus 9000 Application Centric Infrastructure (ACI) Mode switches with software before 11.0(1c) allow remote attackers to cause a denial of service (device reload) via an IPv4 ICMP packet with the IP Record Route option, aka Bug ID CSCuq57512.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-310,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-663hn-51_firmware | - |
| zyxel | vmg4380-b10a_firmware | - |
| zyxel | nwa1100-n_firmware | - |
| zyxel | nwa1123-ni_firmware | - |
| zyxel | sbg3300-nb00_firmware | - |
| zyxel | vmg1312-b30a_firmware | - |
| zyxel | nwa1123-ac_firmware | - |
| zyxel | sbg3500-n000_firmware | - |
| zyxel | nwa1121-ni_firmware | - |
| zyxel | fr1000z_firmware | - |
| zyxel | c1000z_firmware | - |
| zyxel | p8702n_firmware | - |
| zyxel | sbg3300-n000_firmware | - |
| zyxel | gs1900-8_firmware | - |
| zyxel | vmg8924-b30a_firmware | - |
| zyxel | vmg1312-b30b_firmware | - |
| zyxel | vmg8924-b10a_firmware | - |
| zyxel | nwa1100-nh_firmware | - |
| zyxel | pmg5318-b20a_firmware | - |
| zyxel | vmg8324-b10a_firmware | - |
| zyxel | vsg1435-b101_firmware | - |
| zyxel | q1000_firmware | - |
| zyxel | p-660hn-51_firmware | - |
| zyxel | vmg1312-b10a_firmware | - |
| zyxel | gs1900-24_firmware | - |
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg-418n_firmware | 1.00(aadz.3)c0 |
Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg-418n | * |
| zyxel | nbg-418n_firmware | 1.00(aadz.3)c0 |
Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | usg50_firmware | - |
| zyxel | nwa3560-n_firmware | - |
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | pk5001z_firmware | - |
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-284,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | opensolaris | snv_124 |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| cisco | nx-os | base |
| zyxel | gs1900-10hp_firmware | * |
The Openfire server in Cisco Finesse Desktop 10.5(1) and 11.0(1) and Unified Contact Center Express 10.6(1) has a hardcoded account, which makes it easier for remote attackers to obtain access via an XMPP session, aka Bug ID CSCuw79085.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-255,CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zzinc | keymouse_firmware | 3.08 |
| zyxel | gs1900-10hp_firmware | * |
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | gs1900-10hp_firmware | * |
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-200,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | opensolaris | snv_124 |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| zyxel | gs1900-10hp_firmware | * |
Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| sun | opensolaris | snv_124 |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| zyxel | gs1900-10hp_firmware | * |
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 3.9s_3.9.0s |
| cisco | ios_xe | 3.4sg_3.4.2sg |
| cisco | ios_xe | 3.10s_3.10.5s |
| cisco | ios_xe | 3.8e_3.8.1e |
| cisco | ios_xe | 3.16s_3.16.1s |
| cisco | ios_xe | 3.4s_3.4.1s |
| cisco | ios_xe | 3.9s_3.9.0as |
| cisco | ios_xe | 3.10s_3.10.3s |
| cisco | ios_xe | 3.12s_3.12.0s |
| cisco | ios_xe | 3.4sg_3.4.1sg |
| cisco | ios_xe | 3.7s_3.7.4as |
| cisco | ios_xe | 3.4s_3.4.2s |
| cisco | ios_xe | 3.7s_3.7.2s |
| cisco | ios_xe | 3.11s_3.11.3s |
| cisco | ios_xe | 3.5s_3.5.2s |
| zyxel | gs1900-10hp_firmware | * |
| cisco | ios_xe | 3.15s_3.15.0s |
| cisco | ios_xe | 3.13s_3.13.2s |
| cisco | ios_xe | 3.7s_3.7.1s |
| cisco | ios_xe | 3.3sg_3.3.1sg |
| cisco | ios_xe | 3.7s_3.7.6s |
| cisco | ios_xe | 3.4s_3.4.0s |
| cisco | ios_xe | 3.6e_3.6.2e |
| cisco | ios_xe | 3.12s_3.12.3s |
| cisco | ios_xe | 3.4sg_3.4.0sg |
| zzinc | keymouse_firmware | 3.08 |
| cisco | ios_xe | 3.12s_3.12.2s |
| cisco | ios_xe | 3.14s_3.14.2s |
| cisco | ios_xe | 3.3xo_3.3.1xo |
| cisco | ios_xe | 3.5s_3.5.1s |
| cisco | ios_xe | 3.16s_3.16.0cs |
| cisco | ios_xe | 3.4sg_3.4.3sg |
| cisco | ios_xe | 3.4sg_3.4.7sg |
| cisco | ios_xe | 3.8s_3.8.0s |
| cisco | ios_xe | 3.13s_3.13.1s |
| cisco | ios_xe | 3.6s_3.6.2s |
| netgear | jr6150_firmware | * |
| cisco | ios_xe | 3.6s_3.6.1s |
| cisco | ios_xe | 3.13s_3.13.0s |
| cisco | ios_xe | 3.15s_3.15.2s |
| cisco | ios_xe | 3.15s_3.15.1cs |
| cisco | ios_xe | 3.9s_3.9.2s |
| cisco | ios_xe | 3.13s_3.13.4s |
| cisco | ios_xe | 3.11s_3.11.2s |
| cisco | ios_xe | 3.7s_3.7.5s |
| cisco | ios_xe | 3.5e_3.5.3e |
| cisco | ios_xe | 3.9s_3.9.1as |
| cisco | ios_xe | 3.7s_3.7.2ts |
| cisco | ios_xe | 3.4s_3.4.5s |
| cisco | ios_xe | 3.12s_3.12.1s |
| cisco | ios_xe | 3.5e_3.5.1e |
| cisco | ios_xe | 3.4sg_3.4.5sg |
| cisco | ios_xe | 3.4sg_3.4.6sg |
| cisco | ios_xe | 3.13s_3.13.2as |
| sun | opensolaris | snv_124 |
| cisco | ios_xe | 3.4s_3.4.0as |
| cisco | ios_xe | 3.5e_3.5.0e |
| cisco | ios_xe | 3.7s_3.7.3s |
| cisco | ios_xe | 3.14s_3.14.3s |
| cisco | ios_xe | 3.8s_3.8.1s |
| cisco | ios_xe | 3.11s_3.11.1s |
| cisco | ios_xe | 3.8e_3.8.0e |
| cisco | ios_xe | 3.12s_3.12.4s |
| cisco | ios_xe | 3.16s_3.16.0s |
| cisco | ios_xe | 3.10s_3.10.0s |
| cisco | ios_xe | 3.10s_3.10.6s |
| cisco | ios_xe | 3.3s_3.3.1s |
| cisco | ios_xe | 3.7e_3.7.2e |
| cisco | ios_xe | 3.3sg_3.3.2sg |
| cisco | ios_xe | 3.10s_3.10.1s |
| cisco | ios_xe | 3.3xo_3.3.0xo |
| cisco | ios_xe | 3.6e_3.6.2ae |
| cisco | ios_xe | 3.10s_3.10.4s |
| cisco | ios_xe | 3.14s_3.14.0s |
| lenovo | thinkcentre_e75s_firmware | * |
| cisco | ios_xe | 3.7e_3.7.3e |
| cisco | ios_xe | 3.7e_3.7.0e |
| cisco | ios_xe | 3.9s_3.9.1s |
| cisco | ios_xe | 3.8s_3.8.2s |
| cisco | ios_xe | 3.7s_3.7.0s |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| cisco | ios_xe | 3.6e_3.6.1e |
| cisco | ios_xe | 3.6s_3.6.0s |
| cisco | ios_xe | 3.5e_3.5.2e |
| cisco | ios_xe | 3.6e_3.6.3e |
| cisco | ios_xe | 3.4s_3.4.4s |
| cisco | ios_xe | 3.14s_3.14.1s |
| cisco | ios_xe | 3.3sg_3.3.0sg |
| cisco | ios_xe | 3.4s_3.4.6s |
| cisco | ios_xe | 3.7e_3.7.1e |
| cisco | ios_xe | 3.3s_3.3.2s |
| cisco | ios_xe | 3.3s_3.3.0s |
| cisco | ios_xe | 3.16s_3.16.1as |
| cisco | ios_xe | 3.15s_3.15.1s |
| cisco | ios_xe | 3.6e_3.6.0e |
| cisco | ios_xe | 3.10s_3.10.1xbs |
| cisco | ios_xe | 3.11s_3.11.4s |
| cisco | ios_xe | 3.13s_3.13.3s |
| cisco | ios_xe | 3.3xo_3.3.2xo |
| cisco | ios_xe | 3.17s_3.17.0s |
| cisco | ios_xe | 3.4sg_3.4.4sg |
| cisco | ios_xe | 3.7s_3.7.4s |
| cisco | ios_xe | 3.13s_3.13.0as |
| cisco | ios_xe | 3.7s_3.7.7s |
| cisco | ios_xe | 3.11s_3.11.0s |
| cisco | ios_xe | 3.10s_3.10.2s |
| cisco | ios_xe | 3.4s_3.4.3s |
| cisco | ios_xe | 3.5s_3.5.0s |
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| netgear | jr6150_firmware | * |
| zyxel | gs1900-10hp_firmware | * |
| dell | emc_powerscale_onefs | 8.2.2 |
Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 3.8e_3.8.0e |
| cisco | ios_xe | 3.11s_3.11.1s |
| cisco | ios_xe | 3.9s_3.9.0s |
| cisco | ios_xe | 3.10s_3.10.5s |
| cisco | ios_xe | 3.12s_3.12.4s |
| cisco | ios_xe | 3.16s_3.16.0s |
| cisco | ios_xe | 3.10s_3.10.0s |
| cisco | ios_xe | 3.16s_3.16.1s |
| cisco | ios_xe | 3.10s_3.10.6s |
| cisco | ios_xe | 3.9s_3.9.0as |
| cisco | ios_xe | 3.10s_3.10.3s |
| cisco | ios_xe | 3.7e_3.7.2e |
| cisco | ios_xe | 3.12s_3.12.0s |
| cisco | ios_xe | 3.7s_3.7.4as |
| cisco | ios_xe | 3.7s_3.7.2s |
| cisco | ios_xe | 3.10s_3.10.1s |
| cisco | ios_xe | 3.3xo_3.3.0xo |
| cisco | ios_xe | 3.11s_3.11.3s |
| cisco | ios_xe | 3.6e_3.6.2ae |
| cisco | ios_xe | 3.5s_3.5.2s |
| cisco | ios_xe | 3.10s_3.10.4s |
| zyxel | gs1900-10hp_firmware | * |
| cisco | ios_xe | 3.15s_3.15.0s |
| cisco | ios_xe | 3.14s_3.14.0s |
| cisco | ios_xe | 3.13s_3.13.2s |
| cisco | ios_xe | 3.7s_3.7.1s |
| cisco | ios_xe | 3.7s_3.7.6s |
| cisco | ios_xe | 3.6e_3.6.2e |
| cisco | ios_xe | 3.7e_3.7.0e |
| cisco | ios_xe | 3.9s_3.9.1s |
| cisco | ios_xe | 3.12s_3.12.3s |
| cisco | ios_xe | 3.8s_3.8.2s |
| cisco | ios_xe | 3.7s_3.7.0s |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| cisco | ios_xe | 3.6e_3.6.1e |
| cisco | ios_xe | 3.6s_3.6.0s |
| cisco | ios_xe | 3.12s_3.12.2s |
| cisco | ios_xe | 3.5e_3.5.2e |
| cisco | ios_xe | 3.14s_3.14.2s |
| cisco | ios_xe | 3.3xo_3.3.1xo |
| cisco | ios_xe | 3.5s_3.5.1s |
| cisco | ios_xe | 3.6e_3.6.3e |
| cisco | ios_xe | 3.16s_3.16.0cs |
| cisco | ios_xe | 3.8s_3.8.0s |
| cisco | ios_xe | 3.13s_3.13.1s |
| cisco | ios_xe | 3.6s_3.6.2s |
| netgear | jr6150_firmware | * |
| cisco | ios_xe | 3.6s_3.6.1s |
| cisco | ios_xe | 3.13s_3.13.0s |
| cisco | ios_xe | 3.15s_3.15.2s |
| cisco | ios_xe | 3.14s_3.14.1s |
| cisco | ios_xe | 3.15s_3.15.1cs |
| cisco | ios_xe | 3.9s_3.9.2s |
| cisco | ios_xe | 3.7e_3.7.1e |
| cisco | ios_xe | 3.15s_3.15.1s |
| cisco | ios_xe | 3.16s_3.16.1as |
| cisco | ios_xe | 3.6e_3.6.0e |
| cisco | ios_xe | 3.13s_3.13.4s |
| cisco | ios_xe | 3.11s_3.11.2s |
| cisco | ios_xe | 3.10s_3.10.1xbs |
| cisco | ios_xe | 3.7s_3.7.5s |
| cisco | ios_xe | 3.11s_3.11.4s |
| cisco | ios_xe | 3.5e_3.5.3e |
| cisco | ios_xe | 3.9s_3.9.1as |
| cisco | ios_xe | 3.7s_3.7.2ts |
| cisco | ios_xe | 3.13s_3.13.3s |
| cisco | ios_xe | 3.5e_3.5.1e |
| cisco | ios_xe | 3.12s_3.12.1s |
| cisco | ios_xe | 3.3xo_3.3.2xo |
| cisco | ios_xe | 3.13s_3.13.2as |
| cisco | ios_xe | 3.7s_3.7.4s |
| sun | opensolaris | snv_124 |
| cisco | ios_xe | 3.13s_3.13.0as |
| cisco | ios_xe | 3.7s_3.7.7s |
| cisco | ios_xe | 3.5e_3.5.0e |
| cisco | ios_xe | 3.11s_3.11.0s |
| cisco | ios_xe | 3.7s_3.7.3s |
| cisco | ios_xe | 3.14s_3.14.3s |
| cisco | ios_xe | 3.10s_3.10.2s |
| cisco | ios_xe | 3.8s_3.8.1s |
| cisco | ios_xe | 3.5s_3.5.0s |
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 3.4sg_3.4.2sg |
| cisco | ios_xe | 3.4sg_3.4.3sg |
| intel | core_i5-9400f_firmware | - |
| netgear | jr6150_firmware | * |
| cisco | ios_xe | 3.2se_3.2.2se |
| cisco | ios_xe | 3.2se_3.2.0se |
| cisco | ios_xe | 3.7e_3.7.2e |
| cisco | ios_xe | 3.3se_3.3.4se |
| cisco | ios_xe | 3.2se_3.2.1se |
| cisco | ios_xe | 3.4sg_3.4.1sg |
| cisco | ios_xe | 3.3xo_3.3.0xo |
| cisco | ios_xe | 3.3se_3.3.1se |
| cisco | ios_xe | 3.6e_3.6.2ae |
| cisco | ios_xe | 3.3se_3.3.2se |
| cisco | ios_xe | 3.7e_3.7.1e |
| zyxel | gs1900-10hp_firmware | * |
| cisco | ios_xe | 3.2se_3.2.3se |
| cisco | ios_xe | 3.6e_3.6.0e |
| cisco | ios_xe | 3.5e_3.5.3e |
| cisco | ios_xe | 3.3se_3.3.3se |
| cisco | ios_xe | 3.6e_3.6.2e |
| cisco | ios_xe | 3.5e_3.5.1e |
| cisco | ios_xe | 3.7e_3.7.0e |
| cisco | ios_xe | 3.3xo_3.3.2xo |
| cisco | ios_xe | 3.4sg_3.4.5sg |
| cisco | ios_xe | 3.4sg_3.4.0sg |
| cisco | ios_xe | 3.4sg_3.4.4sg |
| cisco | ios_xe | 3.3se_3.3.0se |
| cisco | ios_xe | 3.4sg_3.4.6sg |
| cisco | ios_xe | 3.2ja_3.2.0ja |
| cisco | ios_xe | 3.3se_3.3.5se |
| sun | opensolaris | snv_124 |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| zzinc | keymouse_firmware | 3.08 |
| cisco | ios_xe | 3.5e_3.5.0e |
| cisco | ios_xe | 3.6e_3.6.1e |
| cisco | ios_xe | 3.5e_3.5.2e |
| cisco | ios_xe | 3.3xo_3.3.1xo |
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 3.10.0s |
| lenovo | thinkcentre_e75s_firmware | * |
| cisco | ios_xe | 3.10.2s |
| cisco | ios_xe | 3.8.2s |
| cisco | ios_xe | 3.9.1as |
| cisco | ios_xe | 3.10.1xbs |
| cisco | ios_xe | 3.9.1s |
| cisco | ios_xe | 3.9.2s |
| cisco | ios_xe | 3.9.0s |
| cisco | ios_xe | 3.9.0as |
| sun | opensolaris | snv_124 |
| samsung | x14j_firmware | t-ms14jakucb-1102.5 |
| cisco | ios_xe | 3.11.0s |
| cisco | ios_xe | 3.10.1s |
| zzinc | keymouse_firmware | 3.08 |
| cisco | ios_xe | 3.8.0s |
| cisco | ios_xe | 3.8.1s |
| zyxel | gs1900-10hp_firmware | * |
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg6716_firmware | 1.00(aakg.9)c0 |
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | zywall_usg_100_firmware | 3.30(aqq.7) |
| zyxel | zywall_usg_100_firmware | 2.12(aqq.2) |
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-400,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw_firmware | - |
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v2_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.15.0 |
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p660hn-t1a_v2_firmware | 7.3.37.6 |
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.37.6 |
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p660hn-t1a_v2_firmware | 7.3.37.6 |
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.37.6 |
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v2_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.15.0 |
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| billion | 5200w-t_firmware | 7.3.8.0 |
| zyxel | p660hn-t1a_v2_firmware | 7.3.15.0 |
| zyxel | p660hn-t1a_v1_firmware | 7.3.15.0 |
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | max318m_firmware | - |
| huawei | bm2022_firmware | - |
| zyxel | max218m1w_firmware | - |
| huawei | hes-319m_firmware | - |
| huawei | hes-339m_firmware | - |
| zyxel | max218mw_firmware | - |
| zyxel | max308m_fimware | - |
| mada | soho_wireless_router_firmware | - |
| zyxel | max218m_firmware | - |
| huawei | hes-319m2w_firmware | - |
| zte | ox-330p_firmware | - |
| huawei | hes-309m_firmware | - |
| greenpacket | ox350_firmware | - |
| zyxel | max338m_firmware | - |
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2.8 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | emg2926_firmware | v1.00(aaqt.4)b8 |
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-1188,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | wre6505_firmware | * |
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by improper access controls that allow access to critical functions without authentication. An attacker can use this vulnerability to reboot affected devices, along with other actions. Was ZDI-CAN-4540.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,CWE-732,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-870h-51_firmware | 1.00(awg.3)d5 |
Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow attackers to perform state-changing actions via crafted HTTP forms.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nsa325_v2_firmware | 4.81 |
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-77,CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nsa325_v2_firmware | 4.81 |
Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatus-hostEntry.cmd hostname parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | vmg3312_b10b_firmware | - |
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | vmg3312-b10b_firmware | 1.00(aapp.7) |
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | vmg1312-b10d_firmware | * |
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented UDP packets.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hw_v3_firmware | - |
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | usg_20w-vpn_firmware | - |
| zyxel | usg_40w_firmware | - |
| zyxel | usg_60w_firmware | - |
| zyxel | zywall_vpn_100_firmware | - |
| zyxel | usg_110_firmware | - |
| zyxel | usg_310_firmware | - |
| zyxel | usg_60_firmware | - |
| zyxel | zywall_vpn_300_firmware | - |
| zyxel | zywall_110_firmware | - |
| zyxel | zywall_310_firmware | - |
| zyxel | usg_2200-vpn_firmware | - |
| zyxel | usg_40_firmware | - |
| zyxel | zywall_vpn_50_firmware | - |
| zyxel | zywall_1100_firmware | - |
| zyxel | usg_20w_firmware | - |
| zyxel | usg_1100_firmware | - |
| zyxel | usg_1900_firmware | - |
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system. Furthermore, an attacker can start the device's TELNET service as a backdoor.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | ac3000_firmware | - |
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-522,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nas326_firmware | * |
Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nas326_firmware | * |
A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged user to change the location of any other user's files.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nas326_firmware | * |
An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nas326_firmware | * |
An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or HTML via the user, group, and file-share description fields.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nas326_firmware | * |
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | uag2100_firmware | * |
| zyxel | uag5100_firmware | * |
| zyxel | usg310_firmware | * |
| zyxel | usg2200-vpn_firmware | * |
| zyxel | usg110_firmware | * |
| zyxel | usg1100_firmware | * |
| zyxel | usg1900_firmware | * |
| zyxel | uag4100_firmware | * |
| zyxel | usg210_firmware | * |
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-425,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | usg310_firmware | * |
| zyxel | uag2100_firmware | * |
| zyxel | usg2200-vpn_firmware | * |
| zyxel | zywall_1100_firmware | * |
| zyxel | usg110_firmware | * |
| zyxel | usg1100_firmware | * |
| zyxel | uag4100_firmware | * |
| zyxel | usg210_firmware | * |
| zyxel | uag5100_firmware | * |
| zyxel | zywall_110_firmware | * |
| zyxel | usg1900_firmware | * |
| zyxel | zywall_vpn100_firmware | * |
| zyxel | zywall_vpn300_firmware | * |
| zyxel | zywall_310_firmware | * |
ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized user to access certain pages that require admin privileges.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-639,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | 2.00(abbx.3) | - |
wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.4 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H | 3.9 | 5.5 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg-418n_v2_firmware | 1.00(aarp.9)c0 |
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | nbg-418n_firmware | 1.00(aaxm.6)c0 |
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | p-660hn-t1_firmware | 2.00(aakk.3) |
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | dsl-491hnu-b10b_firmware | - |
| zyxel | dsl-491hnu-b1b_v2_firmware | - |
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| zyxel | vpn300_firmware | - |
| zyxel | atp200_firmware | 4.31 |
| zyxel | usg110_firmware | 4.31 |
| zyxel | vpn100_firmware | - |
| zyxel | usg310_firmware | 4.31 |
| zyxel | zywall_110_firmware | 4.31 |
| zyxel | atp500_firmware | 4.31 |
| zyxel | usg210_firmware | 4.31 |
| zyxel | usg1100_firmware | 4.31 |
| zyxel | usg20w-vpn_firmware | 4.31 |
| zyxel | usg60_firmware | 4.31 |
| zyxel | usg40w_firmware | 4.31 |
| zyxel | usg20-vpn_firmware | 4.31 |
| zyxel | usg1900_firmware | 4.31 |
| zyxel | zywall_310_firmware | 4.31 |
| zyxel | usg2200-vpn_firmware | 4.31 |
| zyxel | zywall_1100_firmware | 4.31 |
| zyxel | atp800_firmware | 4.31 |
| zyxel | usg40_firmware | 4.31 |
| zyxel | vpn50_firmware | - |
| zyxel | usg60w_firmware | 4.31 |