cbcvebase.

Zyxel Atp100W Firmware vulnerabilities

23 known vulnerabilities affecting zyxel/atp100w_firmware.

Total CVEs
23
CISA KEV
5
actively exploited
Public exploits
6
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH9MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2022-40603P4MEDIUMCVSS 6.1≥ 4.32, ≤ 5.312022-12-06
CVE-2022-40603 [MEDIUM] CWE-79 CVE-2022-40603: A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware ve A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL
nvd
CVE-2023-6397P4MEDIUMCVSS 5.3≥ 4.32, < 5.37v5.372024-02-20
CVE-2023-6397 [MEDIUM] CWE-476 CVE-2023-6397: A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feat
nvd
CVE-2023-27990P4MEDIUMCVSS 4.8≥ 4.32, < 5.362023-04-24
CVE-2023-27990 [MEDIUM] CWE-79 CVE-2023-27990: The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35 The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker
nvd
Zyxel Atp100W Firmware vulnerabilities | cvebase