CVE-2022-45440
- EPSS 0.11%
- Veröffentlicht 17.01.2023 02:15:09
- Zuletzt bearbeitet 17.12.2025 09:15:50
A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability t...
CVE-2022-45439
- EPSS 0.22%
- Veröffentlicht 17.01.2023 02:15:09
- Zuletzt bearbeitet 06.12.2024 07:15:04
A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has...
CVE-2022-43392
- EPSS 0.56%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:23
A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.
CVE-2022-43391
- EPSS 1.42%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:23
A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.
CVE-2022-43390
- EPSS 2.5%
- Veröffentlicht 11.01.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:26:23
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
CVE-2022-26414
- EPSS 0.04%
- Veröffentlicht 11.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:54
A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0, which could be exploited by a local authenticated attacker to cause a denial of service.
- EPSS 0.63%
- Veröffentlicht 11.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:54
A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.
CVE-2021-35036
- EPSS 0.15%
- Veröffentlicht 01.03.2022 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:11:43
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.