target entity

Zyxel

12 source-linked records in the current knowledge graph.

high

CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2024-40891EPSS 22.0%DSL CPE DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-40890: Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CVE-2024-40890EPSS 22.4%DSL CPE DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerability

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-11667EPSS 3.0%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6884: Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-6884EPSS 37.6%EMG2926 RoutersZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2017-18368: Zyxel P660HN-T1A Routers Command Injection Vulnerability

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2017-18368EPSS 94.5%P660HN-T1A RoutersZyxel
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-27992: Zyxel Multiple NAS Devices Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability that could allow an unauthenticated attacker to execute commands remotely via a crafted HTTP request. Required action: Apply updates per vendor instructions.

CVE-2023-27992EPSS 84.2%Multiple Network-Attached Storage (NAS) DevicesZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33009EPSS 28.1%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33010EPSS 28.8%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-28771EPSS 99.3%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-9054: Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code. Required action: Apply updates per vendor instructions.

CVE-2020-9054EPSS 100.0%Multiple Network-Attached Storage (NAS) DevicesZyxel
CISA KEV ↗ · unattributed attribution