CVE-2024-11667
- EPSS 50.99%
- Published 27.11.2024 10:15:04
- Last modified 05.12.2024 18:41:12
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG...
CVE-2024-42061
- EPSS 0.23%
- Published 03.09.2024 03:15:03
- Last modified 13.12.2024 16:14:38
A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware ve...
CVE-2024-7203
- EPSS 1.48%
- Published 03.09.2024 02:15:05
- Last modified 13.12.2024 16:14:32
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to...
CVE-2024-6343
- EPSS 0.19%
- Published 03.09.2024 02:15:05
- Last modified 13.12.2024 16:14:42
A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20...
CVE-2024-42060
- EPSS 1.48%
- Published 03.09.2024 02:15:04
- Last modified 13.12.2024 16:14:40
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and US...
CVE-2024-42059
- EPSS 1.48%
- Published 03.09.2024 02:15:04
- Last modified 13.12.2024 16:14:36
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and US...
CVE-2024-42058
- EPSS 0.22%
- Published 03.09.2024 02:15:04
- Last modified 13.12.2024 16:14:34
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN se...
CVE-2024-42057
- EPSS 6.27%
- Published 03.09.2024 02:15:04
- Last modified 13.12.2024 16:14:44
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, a...
CVE-2023-5797
- EPSS 0.05%
- Published 28.11.2023 03:15:07
- Last modified 21.11.2024 08:42:30
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20...
CVE-2023-5960
- EPSS 0.07%
- Published 28.11.2023 03:15:07
- Last modified 21.11.2024 08:42:52
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system...