Zyxel

Zld

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 28.11.2023 02:15:43
  • Zuletzt bearbeitet 21.11.2024 08:42:11

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN serie...

  • EPSS 0.19%
  • Veröffentlicht 28.11.2023 02:15:43
  • Zuletzt bearbeitet 21.11.2024 08:35:03

An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmwar...

  • EPSS 0.04%
  • Veröffentlicht 28.11.2023 02:15:42
  • Zuletzt bearbeitet 21.11.2024 08:35:03

A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series firmware version 5.37, and USG20(W)-VPN series firmware version 5.37, could allow an authenticated local attac...

  • EPSS 0.03%
  • Veröffentlicht 28.11.2023 02:15:42
  • Zuletzt bearbeitet 21.11.2024 08:12:29

A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 th...

  • EPSS 0.07%
  • Veröffentlicht 28.11.2023 02:15:42
  • Zuletzt bearbeitet 21.11.2024 08:12:29

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20...

  • EPSS 0.12%
  • Veröffentlicht 28.11.2023 02:15:42
  • Zuletzt bearbeitet 21.11.2024 08:08:00

A cross-site scripting (XSS) vulnerability in the CGI program of the Zyxel ATP series firmware versions 5.10 through 5.37, USG FLEX series firmware versions 5.00 through 5.37, USG FLEX 50(W) series firmware versions 5.10 through 5.37, USG20(W)-VPN se...

  • EPSS 0.09%
  • Veröffentlicht 28.11.2023 02:15:42
  • Zuletzt bearbeitet 21.11.2024 08:08:00

An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-V...

  • EPSS 3.61%
  • Veröffentlicht 27.12.2020 06:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:53

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week...

  • EPSS 2%
  • Veröffentlicht 27.11.2020 18:15:11
  • Zuletzt bearbeitet 12.12.2024 16:23:25

A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.