Zyxel Nbg-418N Firmware vulnerabilities

8 known vulnerabilities affecting zyxel/nbg-418n_firmware.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-22922HIGHCVSS 7.5≤ 1.00\(aarp.13\)c02023-05-01
CVE-2023-22922 [HIGH] CWE-120 CVE-2023-22922: A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote unauthenticated attacker to cause DoS conditions by sending crafted packets if Telnet is enabled on a vulnerable device.
nvd
CVE-2023-22921HIGHCVSS 7.5≤ 1.00\(aarp.13\)c02023-05-01
CVE-2023-22921 [HIGH] CWE-79 CVE-2023-22921: A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00 A cross-site scripting (XSS) vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to store malicious scripts using a web management interface parameter, resulting in denial-of-service (DoS) conditions on an affected device.
nvd
CVE-2023-22924MEDIUMCVSS 4.9≤ 1.00\(aarp.13\)c02023-05-01
CVE-2023-22924 [MEDIUM] CWE-120 CVE-2023-22924: A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device.
nvd
CVE-2023-22923MEDIUMCVSS 6.5≤ 1.00\(aarp.13\)c02023-05-01
CVE-2023-22923 [MEDIUM] CWE-134 CVE-2023-22923: A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00( A format string vulnerability in a binary of the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker to cause denial-of-service (DoS) conditions on an affected device.
nvd
CVE-2022-45441MEDIUMCVSS 6.1≤ 1.00\(aarp.10\)c02023-02-07
CVE-2022-45441 [MEDIUM] CWE-79 CVE-2022-45441: A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AAR A cross-site scripting (XSS) vulnerability in Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.13)C0, which could allow an attacker to store malicious scripts in the Logs page of the GUI on a vulnerable device. A successful XSS attack could force an authenticated user to execute the stored malicious scripts and then result in a denial-of-servi
nvd
CVE-2019-6710HIGHCVSS 8.8PoCv1.00\(aaxm.6\)c02019-03-07
CVE-2019-6710 [HIGH] CWE-352 CVE-2019-6710: Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF. Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
nvd
CVE-2015-7283HIGHCVSS 8.1v1.00\(aadz.3\)c02015-12-31
CVE-2015-7283 [HIGH] CWE-255 CVE-2015-7283: The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a defaul The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
nvd
CVE-2015-7284HIGHCVSS 8.0v1.00\(aadz.3\)c02015-12-31
CVE-2015-7284 [HIGH] CWE-352 CVE-2015-7284: Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3) Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.
nvd